Generated by JEB on 2019/08/01

PE: C:\Windows\System32\dbgcore.dll Base=0x180000000 SHA-256=C84BECA73EA45D3C53D9C42CD6A37CC0CC07FF57D9CFEE113CDF70F640572AEF
PDB: dbgcore.pdb GUID={899BBC1C-2AF7-9D11-863A194EAED3091B} Age=1

1375 located named symbols:
0x18001F260: "CreateSemaphoreW" ??_C@_0BB@MEFPJLHN@CreateSemaphoreW?$AA@
0x18001E858: "NtQuerySystemInformation" ??_C@_0BJ@NDLOPGCH@NtQuerySystemInformation?$AA@
0x180009840: "public: virtual unsigned long __cdecl GenClrDataEnumMemoryRegionsCallback::Release(void) __ptr64" ?Release@GenClrDataEnumMemoryRegionsCallback@@UEAAKXZ
0x18001853C: "void * __ptr64 __cdecl GenImageDirectoryEntryToData(void * __ptr64,unsigned char,unsigned short,unsigned long * __ptr64)" ?GenImageDirectoryEntryToData@@YAPEAXPEAXEGPEAK@Z
0x18001C5A8: "amd64" ??_C@_1M@OKAPLDDA@?$AAa?$AAm?$AAd?$AA6?$AA4?$AA?$AA@
0x18001F078: "DebugBreak" ??_C@_0L@BPHFKDHF@DebugBreak?$AA@
0x180027CB0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreHandleCallNames" ?g_CoreHandleCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001E938: "NtOpenProcessToken" ??_C@_0BD@EIILLDLN@NtOpenProcessToken?$AA@
0x1800250D8: "struct _CORE_HANDLE_CALLS volatile g_CoreHandleCalls" ?g_CoreHandleCalls@@3U_CORE_HANDLE_CALLS@@C
0x180025DD0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreSynchCallsDesc" ?g_CoreSynchCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001BA48: "__cdecl _imp_LockResource" __imp_LockResource
0x180019734: "__cdecl _raise_securityfailure" __raise_securityfailure
0x180008110: "public: virtual long __cdecl Win32LiveSystemProvider::OpenMapping(unsigned short const * __ptr64,unsigned long * __ptr64,unsigned short * __ptr64,unsigned long,void * __ptr64 * __ptr64) __ptr64" ?OpenMapping@Win32LiveSystemProvider@@UEAAJPEBGPEAKPEAGKPEAPEAX@Z
0x18001E5B8: "__cdecl GUID_3721a26f_8b91_4d98_a388_db17b356fadb" _GUID_3721a26f_8b91_4d98_a388_db17b356fadb
0x18001EEA8: "RtlInitAnsiString" ??_C@_0BC@CEABAGMB@RtlInitAnsiString?$AA@
0x18001E6B8: "PssQuerySnapshot" ??_C@_0BB@HMNBAOEH@PssQuerySnapshot?$AA@
0x18001B9C8: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x1800274B0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_Crypt32CallNames" ?g_Crypt32CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180019B04: "void __cdecl __scrt_initialize_type_info(void)" ?__scrt_initialize_type_info@@YAXXZ
0x180025020: "struct _OLEAUT32_CALLS volatile g_OleAut32Calls" ?g_OleAut32Calls@@3U_OLEAUT32_CALLS@@C
0x180020480: "WNetAddConnection2W" ??_C@_0BE@COECOAIH@WNetAddConnection2W?$AA@
0x18000F760: "public: virtual long __cdecl GenClrDataEnumMemoryRegionsCallback::EnumMemoryRegion(unsigned __int64,unsigned int) __ptr64" ?EnumMemoryRegion@GenClrDataEnumMemoryRegionsCallback@@UEAAJ_KI@Z
0x18001E7C8: "PssNtQuerySnapshot" ??_C@_0BD@MPIMJED@PssNtQuerySnapshot?$AA@
0x18001B3F8: "const PssNtWin32LiveSystemProvider::`vftable'{for `MiniDumpSystemProvider'}" ??_7PssNtWin32LiveSystemProvider@@6BMiniDumpSystemProvider@@@
0x1800190F0: "long __cdecl InitDynamicCalls(struct _DYNAMIC_CALLS_DESC volatile * __ptr64)" ?InitDynamicCalls@@YAJPECU_DYNAMIC_CALLS_DESC@@@Z
0x18001EF38: "RtlGetEnabledExtendedFeatures" ??_C@_0BO@LGBHAKJM@RtlGetEnabledExtendedFeatures?$AA@
0x18001E408: "GenWriteHandleData.Header.Write(" ??_C@_0DF@FCLLGGHM@GenWriteHandleData?4Header?4Write?$CI@
0x180009E04: "private: long __cdecl Win32LiveSystemProvider::VerifyModuleIsTrusted(unsigned short const * __ptr64) __ptr64" ?VerifyModuleIsTrusted@Win32LiveSystemProvider@@AEAAJPEBG@Z
0x18001E8A8: "NtQueryMutant" ??_C@_0O@FEOFHACP@NtQueryMutant?$AA@
0x180015DB0: "public: virtual long __cdecl NtWin32LiveSystemProvider::StartProcessEnum(void * __ptr64,unsigned long) __ptr64" ?StartProcessEnum@NtWin32LiveSystemProvider@@UEAAJPEAXK@Z
0x18000A6A0: "public: virtual long __cdecl Win32LiveSystemProvider::QueryProcessVmCounters(void * __ptr64,struct _MINIDUMP_PROCESS_VM_COUNTERS_2 * __ptr64,unsigned long) __ptr64" ?QueryProcessVmCounters@Win32LiveSystemProvider@@UEAAJPEAXPEAU_MINIDUMP_PROCESS_VM_COUNTERS_2@@K@Z
0x18001A3C4: towlower
0x18001EB78: "\Device\IPT" ??_C@_1BI@JCJLLHAP@?$AA?2?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?2?$AAI?$AAP?$AAT?$AA?$AA@
0x180017D10: "public: virtual long __cdecl NtWin32LiveSystemProvider::QuerySystemMemoryInformation(struct _MINIDUMP_SYSTEM_MEMORY_INFO_1 * __ptr64,unsigned long) __ptr64" ?QuerySystemMemoryInformation@NtWin32LiveSystemProvider@@UEAAJPEAU_MINIDUMP_SYSTEM_MEMORY_INFO_1@@K@Z
0x18001DE48: "ProcessToken_PrimaryGroup(0x%08X" ??_C@_0CL@EMCJJFFI@ProcessToken_PrimaryGroup?$CI0x?$CF08X@
0x18000D61C: "long __cdecl GenReadTlsDirectory(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_MODULE * __ptr64,unsigned char,unsigned long)" ?GenReadTlsDirectory@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_MODULE@@EK@Z
0x180018190: OpenIptDevice
0x18001F100: "ProcessIdToSessionId" ??_C@_0BF@LAKOGFOC@ProcessIdToSessionId?$AA@
0x1800219F0: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x18001E748: "PssWalkMarkerSeek" ??_C@_0BC@FAJOAKBP@PssWalkMarkerSeek?$AA@
0x18001F008: "RtlLocateLegacyContext" ??_C@_0BH@OADANMBG@RtlLocateLegacyContext?$AA@
0x18001BBB8: "__cdecl _imp__o__execute_onexit_table" __imp__o__execute_onexit_table
0x18001A3C4: "__cdecl o_towlower" _o_towlower
0x18001CC98: "Invalid dump type 0x%x" ??_C@_0BH@MHGNOKNM@Invalid?5dump?5type?50x?$CFx?$AA@
0x18001132C: "public: struct _VA_RANGE_REF * __ptr64 __cdecl MiniFixedAllocator<struct _VA_RANGE_REF>::Alloc(void) __ptr64" ?Alloc@?$MiniFixedAllocator@U_VA_RANGE_REF@@@@QEAAPEAU_VA_RANGE_REF@@XZ
0x1800219DC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-crt-private-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-crt-private-l1-1-0
0x18001BAB8: "__cdecl _imp_VirtualProtect" __imp_VirtualProtect
0x18000358C: "long __cdecl WriteMiscInfo(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteMiscInfo@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x180009350: "public: virtual long __cdecl Win32LiveSystemProvider::EnumModules(unsigned __int64 * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?EnumModules@Win32LiveSystemProvider@@UEAAJPEA_KPEAGK@Z
0x1800235F0: "__cdecl _scrt_current_native_startup_state" __scrt_current_native_startup_state
0x180023018: "__cdecl _security_cookie_complement" __security_cookie_complement
0x1800078E0: "public: virtual void __cdecl NtWin32LiveSystemProvider::Release(void) __ptr64" ?Release@NtWin32LiveSystemProvider@@UEAAXXZ
0x180004E60: "long __cdecl WriteDumpData(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _EXCEPTION_INFO * __ptr64 const,struct _MINIDUMP_USER_STREAM * __ptr64 const,unsigned long,struct _LIST_ENTRY * __ptr64 const)" ?WriteDumpData@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@QEAU_EXCEPTION_INFO@@QEAU_MINIDUMP_USER_STREAM@@KQEAU_LIST_ENTRY@@@Z
0x1800200C8: "ClearEventLogA" ??_C@_0P@CBEAAAPH@ClearEventLogA?$AA@
0x18001D618: "GetFileVersionInfoExA" ??_C@_0BG@HIPGLPIC@GetFileVersionInfoExA?$AA@
0x180025078: "struct _CORE_FILE_L1_CALLS volatile g_CoreFileL1Calls" ?g_CoreFileL1Calls@@3U_CORE_FILE_L1_CALLS@@C
0x18001C250: "WriteFunctionTableList.Seek(0x%x" ??_C@_0DB@IJOIELLL@WriteFunctionTableList?4Seek?$CI0x?$CFx@
0x18001D6D0: "Alloc(0x%x) failed" ??_C@_0BD@NJNIICJB@Alloc?$CI0x?$CFx?$CJ?5failed?$AA@
0x18001F6B0: "GetPackagePath" ??_C@_0P@NBOPOPO@GetPackagePath?$AA@
0x18001BA00: "__cdecl _imp_HeapDestroy" __imp_HeapDestroy
0x18001CE40: "GetLongPathNameA" ??_C@_0BB@ODMCEOEO@GetLongPathNameA?$AA@
0x180015990: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetThreadOsInfo(void * __ptr64,void * __ptr64,struct _UMINIPROV_THREAD_INFO * __ptr64) __ptr64" ?GetThreadOsInfo@NtWin32LiveSystemProvider@@UEAAJPEAX0PEAU_UMINIPROV_THREAD_INFO@@@Z
0x18001CB98: "GetSystemType.GetOsInfo failed, " ??_C@_0CH@JKEFEGAD@GetSystemType?4GetOsInfo?5failed?0?5@
0x18001F0D0: "Process32FirstW" ??_C@_0BA@FCBGIKMJ@Process32FirstW?$AA@
0x180020250: "CryptDestroyHash" ??_C@_0BB@INPNJGML@CryptDestroyHash?$AA@
0x180007E60: "public: virtual void __cdecl Win32LiveSystemProvider::GetInstructionWindowSize(unsigned long * __ptr64) __ptr64" ?GetInstructionWindowSize@Win32LiveSystemProvider@@UEAAXPEAK@Z
0x180001728: "void __cdecl ScanMemoryRangeForModuleRefs(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned long,enum MEMBLOCK_TYPE)" ?ScanMemoryRangeForModuleRefs@@YAXPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@_KKW4MEMBLOCK_TYPE@@@Z
0x180025080: "struct _CORE_FILE_L2_CALLS volatile g_CoreFileL2Calls" ?g_CoreFileL2Calls@@3U_CORE_FILE_L2_CALLS@@C
0x18001CE98: "GetThreadSelectorEntry" ??_C@_0BH@LFKOKEGN@GetThreadSelectorEntry?$AA@
0x18001E268: "GenWriteHandleData.Seek(0x%x) fa" ??_C@_0CN@FPACHCAJ@GenWriteHandleData?4Seek?$CI0x?$CFx?$CJ?5fa@
0x180014EE8: "public: virtual void * __ptr64 __cdecl NtWin32LiveSystemProvider::`scalar deleting destructor'(unsigned int) __ptr64" ??_GNtWin32LiveSystemProvider@@UEAAPEAXI@Z
0x180020078: "DeleteService" ??_C@_0O@KGGKBBLF@DeleteService?$AA@
0x18001DA90: "GenReadTlsDirectory(0x%I64x, %ws" ??_C@_0DO@JJNAAJ@GenReadTlsDirectory?$CI0x?$CFI64x?0?5?$CFws@
0x18001C640: "WriteDirectoryTable.Seek(0x%x) f" ??_C@_0CO@HJKDEEMF@WriteDirectoryTable?4Seek?$CI0x?$CFx?$CJ?5f@
0x18001E5A8: "__cdecl GUID_bcdd6908_ba2d_4ec5_96cf_df4d5cdcb4a4" _GUID_bcdd6908_ba2d_4ec5_96cf_df4d5cdcb4a4
0x18001BAF8: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x18001EB90: "GetThreadContext" ??_C@_0BB@MBPKHMON@GetThreadContext?$AA@
0x18001FFD8: "CryptBinaryToStringA" ??_C@_0BF@FFJOEAMK@CryptBinaryToStringA?$AA@
0x18001CF98: "api-ms-win-core-file-l1-1-0" ??_C@_0BM@PKAGLIFK@api?9ms?9win?9core?9file?9l1?91?90?$AA@
0x18001A33E: "__cdecl configure_narrow_argv" _configure_narrow_argv
0x18001A440: "__cdecl _vcrt_thread_attach" __vcrt_thread_attach
0x18001CB00: "Invalid exception record paramet" ??_C@_0DA@LABIMEGH@Invalid?5exception?5record?5paramet@
0x18001A434: "__cdecl _CxxFrameHandler3" __CxxFrameHandler3
0x18001E098: "GenGetProcessInfo.EnumModules(0x" ??_C@_0CL@FGIPNAAA@GenGetProcessInfo?4EnumModules?$CI0x@
0x180020240: "CryptCreateHash" ??_C@_0BA@IEJOIHIJ@CryptCreateHash?$AA@
0x18001EC78: "DbgUiConvertStateChangeStructure" ??_C@_0CB@JECHEEEO@DbgUiConvertStateChangeStructure@
0x18001FAC0: "CoCreateGuid" ??_C@_0N@KNBCBJMO@CoCreateGuid?$AA@
0x180025C18: "struct _CORE_TIMEZONE_CALLS volatile g_CoreTimeZoneCalls" ?g_CoreTimeZoneCalls@@3U_CORE_TIMEZONE_CALLS@@C
0x18001A5F0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x18001F088: "DebugBreakProcess" ??_C@_0BC@EPCMMNGB@DebugBreakProcess?$AA@
0x18001C340: "WriteTokenInformation.Write(0x%x" ??_C@_0DH@BCCICGHO@WriteTokenInformation?4Write?$CI0x?$CFx@
0x1800070A0: "public: virtual long __cdecl Win32LiveSystemProvider::Initialize(void) __ptr64" ?Initialize@Win32LiveSystemProvider@@UEAAJXZ
0x18001F598: "ContinueDebugEvent" ??_C@_0BD@CCCFAODI@ContinueDebugEvent?$AA@
0x18001E568: "__cdecl GUID_00000000_0000_0000_c000_000000000046" _GUID_00000000_0000_0000_c000_000000000046
0x18001B9C0: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x18001E898: "NtQueryObject" ??_C@_0O@IFMDHOMC@NtQueryObject?$AA@
0x18000B538: "void __cdecl GenGetDefaultWriteFlags(struct _MINIDUMP_STATE * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64)" ?GenGetDefaultWriteFlags@@YAXPEAU_MINIDUMP_STATE@@PEAK1@Z
0x180025C20: "struct _POWR_PROF_CALLS volatile g_PowrProfCalls" ?g_PowrProfCalls@@3U_POWR_PROF_CALLS@@C
0x180011680: "long __cdecl GenMergeFilterList(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _VA_RANGE_REF * __ptr64 * __ptr64,struct _VA_RANGE_REF * __ptr64)" ?GenMergeFilterList@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAPEAU_VA_RANGE_REF@@PEAU3@@Z
0x180009660: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::WriteKernelMinidump(void * __ptr64,void * __ptr64,unsigned long,void * __ptr64 * __ptr64,unsigned long,unsigned long) __ptr64" ?WriteKernelMinidump@PssNtWin32LiveSystemProvider@@UEAAJPEAX0KPEAPEAXKK@Z
0x18000AC60: "protected: static unsigned long __cdecl Win32LiveSystemProvider::GetFileVersionInfoSizeWStub(unsigned short const * __ptr64,unsigned long * __ptr64)" ?GetFileVersionInfoSizeWStub@Win32LiveSystemProvider@@KAKPEBGPEAK@Z
0x18001B9A8: "__cdecl _imp_CreateFileA" __imp_CreateFileA
0x1800096A0: "public: virtual void __cdecl PssNtWin32LiveSystemProvider::FinishHandleEnum(void) __ptr64" ?FinishHandleEnum@PssNtWin32LiveSystemProvider@@UEAAXXZ
0x18001CE70: "GetProcessTimes" ??_C@_0BA@BDGKEDFH@GetProcessTimes?$AA@
0x18001C610: "WriteHeader.GetCurrentTimeDate f" ??_C@_0CO@LCLHCLFF@WriteHeader?4GetCurrentTimeDate?5f@
0x180027420: "struct _DYNAMIC_CALLS_DESC volatile g_CoreWindowsErrorReportingCallsDesc" ?g_CoreWindowsErrorReportingCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18000ACD0: "protected: static int __cdecl Win32LiveSystemProvider::GetFileVersionInfoWStub(unsigned short const * __ptr64,unsigned long,unsigned long,void * __ptr64)" ?GetFileVersionInfoWStub@Win32LiveSystemProvider@@KAHPEBGKKPEAX@Z
0x18001CDE0: "Module32First" ??_C@_0O@CNMFJJGO@Module32First?$AA@
0x1800277D0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_PowrProfCallNames" ?g_PowrProfCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x1800263E0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_EventlogLegacyCallNames" ?g_EventlogLegacyCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180017198: "private: long __cdecl NtWin32LiveSystemProvider::DupSame(unsigned __int64,void * __ptr64 * __ptr64) __ptr64" ?DupSame@NtWin32LiveSystemProvider@@AEAAJ_KPEAPEAX@Z
0x18001A370: "__cdecl o__purecall" _o__purecall
0x180025C80: "struct _DYNAMIC_CALLS_DESC volatile g_CoreProcessThreadsCallsDesc" ?g_CoreProcessThreadsCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x1800079F0: "public: virtual long __cdecl Win32LiveSystemProvider::QueryMiscInformationEx(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64,struct MISC_EXDATA * __ptr64) __ptr64" ?QueryMiscInformationEx@Win32LiveSystemProvider@@UEAAJPEAXKPEAK0K1PEAUMISC_EXDATA@@@Z
0x180006B4C: "protected: __cdecl Win32LiveSystemProvider::Win32LiveSystemProvider(class MiniDumpAllocationProvider * __ptr64,class MiniDumpStatusProvider * __ptr64,unsigned long,unsigned long) __ptr64" ??0Win32LiveSystemProvider@@IEAA@PEAVMiniDumpAllocationProvider@@PEAVMiniDumpStatusProvider@@KK@Z
0x18001FC08: "WindowsGetStringRawBuffer" ??_C@_0BK@KBEEKJGL@WindowsGetStringRawBuffer?$AA@
0x18000F4F0: "public: virtual long __cdecl GenClrDataTarget::SetThreadContext(unsigned int,unsigned int,unsigned char * __ptr64) __ptr64" ?SetThreadContext@GenClrDataTarget@@UEAAJIIPEAE@Z
0x18001CDC0: "Thread32First" ??_C@_0O@DHAEEPDO@Thread32First?$AA@
0x18001F9C0: "api-ms-win-core-job-l2-1-0.dll" ??_C@_0BP@PIDGFIIH@api?9ms?9win?9core?9job?9l2?91?90?4dll?$AA@
0x180001BB4: "long __cdecl WriteStringToPool(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,unsigned short * __ptr64,unsigned long * __ptr64)" ?WriteStringToPool@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAGPEAK@Z
0x18000EF8C: "long __cdecl GenIncludeUnwindInfoMemory(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_FUNCTION_TABLE * __ptr64)" ?GenIncludeUnwindInfoMemory@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_FUNCTION_TABLE@@@Z
0x180025C30: "struct NTDLL_CALLS_MDWD volatile g_NtDllCallsMdwd" ?g_NtDllCallsMdwd@@3UNTDLL_CALLS_MDWD@@C
0x18001BD10: "__cdecl _xp_a" __xp_a
0x18001BBC0: "__cdecl _imp__o__initialize_narrow_environment" __imp__o__initialize_narrow_environment
0x180009840: "__cdecl is_c_termination_complete" _is_c_termination_complete
0x180020440: "api-ms-win-eventing-provider-l1-" ??_C@_0CI@FPJCNGPM@api?9ms?9win?9eventing?9provider?9l1?9@
0x18001E9F8: "OpenProcessToken" ??_C@_0BB@EANJDCJP@OpenProcessToken?$AA@
0x180025218: "struct _EXT_KERNEL32_PACKAGE_L1_CALLS volatile g_ExtKernel32PackageL1Calls" ?g_ExtKernel32PackageL1Calls@@3U_EXT_KERNEL32_PACKAGE_L1_CALLS@@C
0x18001BAA0: "__cdecl _imp_ReadProcessMemory" __imp_ReadProcessMemory
0x18001F620: "IsDBCSLeadByte" ??_C@_0P@NPDBHJOD@IsDBCSLeadByte?$AA@
0x18001F630: "GetMappedFileNameW" ??_C@_0BD@DENOEEPK@GetMappedFileNameW?$AA@
0x180027650: "struct _DYNAMIC_CALLS_DESC volatile g_ShlWapiCallsDesc" ?g_ShlWapiCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001A094: "__cdecl RTC_Initialize" _RTC_Initialize
0x180009660: "public: virtual long __cdecl Win32LiveSystemProvider::GetThreadName(void * __ptr64,void * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?GetThreadName@Win32LiveSystemProvider@@UEAAJPEAX0PEAGK@Z
0x180007B10: "public: virtual void __cdecl Win32LiveSystemProvider::GetCpuInformation(union _CPU_INFORMATION * __ptr64) __ptr64" ?GetCpuInformation@Win32LiveSystemProvider@@UEAAXPEAT_CPU_INFORMATION@@@Z
0x18001A440: "__cdecl _vcrt_thread_detach" __vcrt_thread_detach
0x18001CD30: "Dump type requires streaming but" ??_C@_0EM@IAANMDKC@Dump?5type?5requires?5streaming?5but@
0x180025498: "struct _CORE_REGISTRY_PRIVATE_CALLS volatile g_CoreRegistryPrivateCalls" ?g_CoreRegistryPrivateCalls@@3U_CORE_REGISTRY_PRIVATE_CALLS@@C
0x180008AD0: "public: virtual long __cdecl Win32LiveSystemProvider::GetThreadContextEx(void * __ptr64,void * __ptr64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned long,bool) __ptr64" ?GetThreadContextEx@Win32LiveSystemProvider@@UEAAJPEAX00KPEA_K11K_N@Z
0x1800186B4: RtlMrdataAcquireSectionWriteAccess
0x18001E968: "NtQueryInformationToken" ??_C@_0BI@JMJKLHAA@NtQueryInformationToken?$AA@
0x18001EE08: "RtlCreateProcessParameters" ??_C@_0BL@JOHNBMND@RtlCreateProcessParameters?$AA@
0x18001F9E0: "api-ms-win-core-localization-l1-" ??_C@_0CI@KJCNGDHP@api?9ms?9win?9core?9localization?9l1?9@
0x18001D6B0: "GetDumpStreams" ??_C@_0P@HAHOPHMI@GetDumpStreams?$AA@
0x18001D658: "GetFileVersionInfoSizeW" ??_C@_0BI@EGKIMOGO@GetFileVersionInfoSizeW?$AA@
0x18001F1E0: "GetApplicationRestartSettings" ??_C@_0BO@PECMODAP@GetApplicationRestartSettings?$AA@
0x18001D8A0: "GenAllocateThreadObject.GetConte" ??_C@_0DI@LADKEKLF@GenAllocateThreadObject?4GetConte@
0x18000F4F0: "public: virtual long __cdecl GenClrDataTarget::SetTLSValue(unsigned int,unsigned int,unsigned __int64) __ptr64" ?SetTLSValue@GenClrDataTarget@@UEAAJII_K@Z
0x18001CF68: "api-ms-win-core-processthreads-l" ??_C@_0CK@FELNBCDF@api?9ms?9win?9core?9processthreads?9l@
0x1800207F0: "__cdecl _rtc_taa" __rtc_taa
0x180021A7C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x1800092B0: "public: virtual long __cdecl Win32LiveSystemProvider::EnumThreads(unsigned long * __ptr64) __ptr64" ?EnumThreads@Win32LiveSystemProvider@@UEAAJPEAK@Z
0x18001CDA0: "kernel32.dll" ??_C@_0N@MDJJJHMB@kernel32?4dll?$AA@
0x18001BC68: "__cdecl _imp__initterm_e" __imp__initterm_e
0x18001B3A0: "const CallbackOutputProvider::`vftable'" ??_7CallbackOutputProvider@@6B@
0x18001F030: "RtlDecompressBufferEx" ??_C@_0BG@ILEIKCNN@RtlDecompressBufferEx?$AA@
0x180006DE0: "public: virtual __cdecl Win32LiveSystemProvider::~Win32LiveSystemProvider(void) __ptr64" ??1Win32LiveSystemProvider@@UEAA@XZ
0x1800099F4: "private: long __cdecl Win32LiveSystemProvider::WintrustVerifyMicrosoftSignature(unsigned short const * __ptr64) __ptr64" ?WintrustVerifyMicrosoftSignature@Win32LiveSystemProvider@@AEAAJPEBG@Z
0x18001BC70: api-ms-win-crt-runtime-l1-1-0_NULL_THUNK_DATA
0x180013DD0: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::EnumHandles(unsigned __int64 * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned short * __ptr64,unsigned long,unsigned short * __ptr64,unsigned long) __ptr64" ?EnumHandles@PssNtWin32LiveSystemProvider@@UEAAJPEA_KPEAK111PEAGK2K@Z
0x18000F068: "long __cdecl GenAddTebMemory(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_THREAD * __ptr64)" ?GenAddTebMemory@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_THREAD@@@Z
0x18001A2DC: "__cdecl _scrt_is_ucrt_dll_in_use" __scrt_is_ucrt_dll_in_use
0x18001C2C8: "WriteFunctionTable.RawTable.Writ" ??_C@_0DH@JLMDIGNE@WriteFunctionTable?4RawTable?4Writ@
0x18000BD30: "long __cdecl GenFilterX86Context(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_THREAD * __ptr64,void * __ptr64,unsigned long,unsigned char)" ?GenFilterX86Context@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_THREAD@@PEAXKE@Z
0x18001A440: "__cdecl _vcrt_initialize" __vcrt_initialize
0x18001BBC8: "__cdecl _imp__initialize_onexit_table" __imp__initialize_onexit_table
0x18001C508: "WriteSystemInfo.GetCpuInfo faile" ??_C@_0CK@JLGGCEKL@WriteSystemInfo?4GetCpuInfo?5faile@
0x180008FD0: "public: virtual long __cdecl Win32LiveSystemProvider::QueryVirtual(void * __ptr64,unsigned __int64,struct _MINIDUMP_MEMORY_INFO * __ptr64) __ptr64" ?QueryVirtual@Win32LiveSystemProvider@@UEAAJPEAX_KPEAU_MINIDUMP_MEMORY_INFO@@@Z
0x18001D128: "api-ms-win-core-kernel32-private" ??_C@_0CM@ONFDGKOB@api?9ms?9win?9core?9kernel32?9private@
0x1800268B0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreLocalizationCallsDesc" ?g_CoreLocalizationCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001BCD8: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x1800253E8: "struct _EXT_MS_WIN_KERNEL32_PACKAGE_L1_1_1_CALLS volatile g_ExtMsWinKernel32PackageL1_1_1Calls" ?g_ExtMsWinKernel32PackageL1_1_1Calls@@3U_EXT_MS_WIN_KERNEL32_PACKAGE_L1_1_1_CALLS@@C
0x1800202D8: "EventWrite" ??_C@_0L@JMEHOADM@EventWrite?$AA@
0x18001FCC8: "SafeArrayCreateVector" ??_C@_0BG@JDANKDAG@SafeArrayCreateVector?$AA@
0x18001D930: "ThreadToken_SessionId(0x%08X,%d," ??_C@_0CH@OKBOPMJI@ThreadToken_SessionId?$CI0x?$CF08X?0?$CFd?0@
0x18001FDC0: "PathIsUNCW" ??_C@_0L@CMJJANNE@PathIsUNCW?$AA@
0x18001F750: "DeriveAppContainerSidFromAppCont" ??_C@_0CK@CNNMHOOI@DeriveAppContainerSidFromAppCont@
0x180008A80: "public: virtual long __cdecl Win32LiveSystemProvider::GetThreadContext(void * __ptr64,void * __ptr64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64) __ptr64" ?GetThreadContext@Win32LiveSystemProvider@@UEAAJPEAX00KPEA_K11@Z
0x18001FE98: "api-ms-win-core-url-l1-1-0.dll" ??_C@_0BP@CIEFPPNB@api?9ms?9win?9core?9url?9l1?91?90?4dll?$AA@
0x18001B2A8: "const GenClrDataTarget::`vftable'" ??_7GenClrDataTarget@@6B@
0x18001BBE8: "__cdecl _imp__o__strlwr_s" __imp__o__strlwr_s
0x18001EA10: "GetTokenInformation" ??_C@_0BE@JIDLIKOL@GetTokenInformation?$AA@
0x18001EED8: "RtlTryEnterCriticalSection" ??_C@_0BL@FHPLGPME@RtlTryEnterCriticalSection?$AA@
0x18001745C: "public: static long __cdecl NtWin32LiveSystemProvider::GetTrueNTVersion(struct _OSVERSIONINFOW * __ptr64)" ?GetTrueNTVersion@NtWin32LiveSystemProvider@@SAJPEAU_OSVERSIONINFOW@@@Z
0x18001FCBC: "VarCmp" ??_C@_06IELNEFAK@VarCmp?$AA@
0x180025368: "struct _SECUR32_CALLS volatile g_Secur32Calls" ?g_Secur32Calls@@3U_SECUR32_CALLS@@C
0x18000B360: "public: virtual void * __ptr64 __cdecl Win32LiveAllocationProvider::Alloc(unsigned long) __ptr64" ?Alloc@Win32LiveAllocationProvider@@UEAAPEAXK@Z
0x18001DE78: "ProcessToken_Privileges(0x%08X,%" ??_C@_0CJ@PGHPPGHC@ProcessToken_Privileges?$CI0x?$CF08X?0?$CF@
0x18000A440: "public: virtual void __cdecl Win32LiveSystemProvider::ReleaseClrEnum(struct ICLRDataEnumMemoryRegions * __ptr64) __ptr64" ?ReleaseClrEnum@Win32LiveSystemProvider@@UEAAXPEAUICLRDataEnumMemoryRegions@@@Z
0x18000A510: "protected: long __cdecl Win32LiveSystemProvider::ProcessThread32First(void * __ptr64,unsigned long,struct tagTHREADENTRY32 * __ptr64) __ptr64" ?ProcessThread32First@Win32LiveSystemProvider@@IEAAJPEAXKPEAUtagTHREADENTRY32@@@Z
0x18001B040: "const Win32LiveSystemProvider::`vftable'{for `MiniDumpSystemProvider'}" ??_7Win32LiveSystemProvider@@6BMiniDumpSystemProvider@@@
0x18001EE28: "RtlCreateUserProcess" ??_C@_0BF@CKCOHCED@RtlCreateUserProcess?$AA@
0x18001FAD0: "CoFreeUnusedLibrariesEx" ??_C@_0BI@KEMHOJLF@CoFreeUnusedLibrariesEx?$AA@
0x18001C428: "QuerySystemMemoryInformation fai" ??_C@_0CM@DJDGLIOI@QuerySystemMemoryInformation?5fai@
0x1800207E0: "__cdecl _rtc_iaa" __rtc_iaa
0x18001F3B0: "GetPrivateProfileSectionW" ??_C@_0BK@OFJMJMM@GetPrivateProfileSectionW?$AA@
0x18001B9B0: "__cdecl _imp_SetFilePointer" __imp_SetFilePointer
0x18001E030: "GenGetProcessInfo.EnumThreads(0x" ??_C@_0CL@FKOMLABF@GenGetProcessInfo?4EnumThreads?$CI0x@
0x18001A440: "__cdecl _acrt_thread_attach" __acrt_thread_attach
0x18001F240: "GetCommandLineA" ??_C@_0BA@MGNOEAPM@GetCommandLineA?$AA@
0x18001F7A8: "CoInitializeEx" ??_C@_0P@KHOCNDJK@CoInitializeEx?$AA@
0x18001DD70: "GenAllocateProcessObject.GetCpuP" ??_C@_0DK@LBDECHDJ@GenAllocateProcessObject?4GetCpuP@
0x180008830: "public: virtual long __cdecl Win32LiveSystemProvider::EnumImageSections(void * __ptr64,unsigned short const * __ptr64,unsigned __int64,unsigned long,class MiniDumpProviderCallbacks * __ptr64) __ptr64" ?EnumImageSections@Win32LiveSystemProvider@@UEAAJPEAXPEBG_KKPEAVMiniDumpProviderCallbacks@@@Z
0x18001F478: "SetConsoleCursorPosition" ??_C@_0BJ@FDNPCKM@SetConsoleCursorPosition?$AA@
0x18001E6F8: "PssWalkMarkerFree" ??_C@_0BC@KLNDFAEF@PssWalkMarkerFree?$AA@
0x180027690: "struct _DYNAMIC_CALL_NAME volatile * volatile g_User32CallNames" ?g_User32CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001ED48: "NtFreeVirtualMemory" ??_C@_0BE@KBMHLKEP@NtFreeVirtualMemory?$AA@
0x18001EDB8: "NtSetInformationProcess" ??_C@_0BI@IMFMFAHN@NtSetInformationProcess?$AA@
0x180009690: "public: virtual long __cdecl Win32LiveSystemProvider::StartHandleEnum(void * __ptr64,unsigned long * __ptr64) __ptr64" ?StartHandleEnum@Win32LiveSystemProvider@@UEAAJPEAXPEAK@Z
0x18001BCE0: "__cdecl _xc_a" __xc_a
0x1800184E0: "void * __ptr64 __cdecl GenAddressInSectionTable(struct _IMAGE_NT_HEADERS64 * __ptr64,void * __ptr64,unsigned long)" ?GenAddressInSectionTable@@YAPEAXPEAU_IMAGE_NT_HEADERS64@@PEAXK@Z
0x18001BC18: "__cdecl _imp_wcsstr" __imp_wcsstr
0x18001E8D0: "RtlFreeHeap" ??_C@_0M@BBFBOFBP@RtlFreeHeap?$AA@
0x18000A7FC: "protected: long __cdecl Win32LiveSystemProvider::LoadPsApi(void) __ptr64" ?LoadPsApi@Win32LiveSystemProvider@@IEAAJXZ
0x18000F4F0: "public: virtual long __cdecl GenClrDataTarget::WriteVirtual(unsigned __int64,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64) __ptr64" ?WriteVirtual@GenClrDataTarget@@UEAAJ_KPEAEIPEAI@Z
0x18000BEAC: "long __cdecl GenFilterAMD64Context(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_THREAD * __ptr64,void * __ptr64,unsigned long,unsigned char)" ?GenFilterAMD64Context@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_THREAD@@PEAXKE@Z
0x18001CEE0: "FindResourceA" ??_C@_0O@JNBDIIDL@FindResourceA?$AA@
0x1800253A8: "struct _VERSION_CALLS volatile g_VersionCalls" ?g_VersionCalls@@3U_VERSION_CALLS@@C
0x18000464C: "long __cdecl WriteFullMemory(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteFullMemory@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x18001E1F0: "GenGetProcessInfo.EnumFunctionTa" ??_C@_0EJ@BPJKEGON@GenGetProcessInfo?4EnumFunctionTa@
0x18001FFC0: "CertOpenSystemStoreW" ??_C@_0BF@KCIKIDHB@CertOpenSystemStoreW?$AA@
0x18000F838: "long __cdecl GenAddAuxProvider(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned short * __ptr64)" ?GenAddAuxProvider@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@_KPEAG@Z
0x180013D10: "public: virtual void __cdecl PssNtWin32LiveSystemProvider::FinishProcessEnum(void) __ptr64" ?FinishProcessEnum@PssNtWin32LiveSystemProvider@@UEAAXXZ
0x1800200E8: "DeregisterEventSource" ??_C@_0BG@LPHFFLAA@DeregisterEventSource?$AA@
0x180001898: "long __cdecl WriteOther(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64)" ?WriteOther@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAXKPEAK@Z
0x18001F7D8: "StringFromGUID2" ??_C@_0BA@HEBEPDDD@StringFromGUID2?$AA@
0x180013120: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::OpenThread(unsigned long,int,unsigned long,void * __ptr64 * __ptr64) __ptr64" ?OpenThread@PssNtWin32LiveSystemProvider@@UEAAJKHKPEAPEAX@Z
0x18001C0C0: "__cdecl pDefaultRawDllMain" _pDefaultRawDllMain
0x18001BBB0: "__cdecl _imp__o__configure_narrow_argv" __imp__o__configure_narrow_argv
0x180014BD8: "public: static void __cdecl PssNtWin32LiveSystemProvider::AVrfpCopyHandleTraceInformation(struct _PROCESS_HANDLE_TRACING_QUERY * __ptr64,unsigned long (__cdecl*)(struct _AVRF_HANDLE_OPERATION * __ptr64,void * __ptr64,unsigned long * __ptr64),void * __ptr64)" ?AVrfpCopyHandleTraceInformation@PssNtWin32LiveSystemProvider@@SAXPEAU_PROCESS_HANDLE_TRACING_QUERY@@P6AKPEAU_AVRF_HANDLE_OPERATION@@PEAXPEAK@Z2@Z
0x180023030: "__cdecl _scrt_ucrt_dll_is_in_use" __scrt_ucrt_dll_is_in_use
0x180001008: IsProcessorFeaturePresent
0x1800257F0: "struct _ADVAPI32_CALLS volatile g_Advapi32Calls" ?g_Advapi32Calls@@3U_ADVAPI32_CALLS@@C
0x18000D5C4: "unsigned short * __ptr64 __cdecl GenGetPathTail(unsigned short * __ptr64)" ?GenGetPathTail@@YAPEAGPEAG@Z
0x18000F660: "public: virtual long __cdecl GenClrDataTarget::GetExceptionContextRecord(unsigned int,unsigned int * __ptr64,unsigned char * __ptr64) __ptr64" ?GetExceptionContextRecord@GenClrDataTarget@@UEAAJIPEAIPEAE@Z
0x18001A394: "__cdecl o__wcsicmp" _o__wcsicmp
0x18001E240: "GenWriteHandleData stream RVA ov" ??_C@_0CH@DKFJHJAA@GenWriteHandleData?5stream?5RVA?5ov@
0x18001C188: "WriteAtOffset.Seek(0x%x) failed," ??_C@_0CI@LNMFPBJJ@WriteAtOffset?4Seek?$CI0x?$CFx?$CJ?5failed?0@
0x18001C8E0: "Too many inaccessible memory blo" ??_C@_0CP@OPBJEEMK@Too?5many?5inaccessible?5memory?5blo@
0x18001DDD0: "ProcessToken_SessionId(0x%08X,%d" ??_C@_0CI@CMKJCBCD@ProcessToken_SessionId?$CI0x?$CF08X?0?$CFd@
0x180025E70: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreConsoleCallNames" ?g_CoreConsoleCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x1800261E0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreProcessEnvironmentCallNames" ?g_CoreProcessEnvironmentCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001BA10: api-ms-win-core-heap-l1-1-0_NULL_THUNK_DATA
0x18001C128: "version.dll" ??_C@_1BI@JADLCDAP@?$AAv?$AAe?$AAr?$AAs?$AAi?$AAo?$AAn?$AA?4?$AAd?$AAl?$AAl?$AA?$AA@
0x18001E9A0: "NtQueryEvent" ??_C@_0N@JEGIMGHC@NtQueryEvent?$AA@
0x18001FDD0: "SHCreateMemStream" ??_C@_0BC@ILNOOBJG@SHCreateMemStream?$AA@
0x18001EE60: "RtlDosPathNameToNtPathName_U" ??_C@_0BN@KHMLLBKI@RtlDosPathNameToNtPathName_U?$AA@
0x18001F160: "Wow64GetThreadSelectorEntry" ??_C@_0BM@GJINBCHA@Wow64GetThreadSelectorEntry?$AA@
0x18001E980: "NtClose" ??_C@_07EGJLEIEB@NtClose?$AA@
0x18001B010: "const Win32LiveSystemProvider::`vftable'{for `MiniDumpVmHookedProvider'}" ??_7Win32LiveSystemProvider@@6BMiniDumpVmHookedProvider@@@
0x1800264F0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreWindowsErrorReportingCallNames" ?g_CoreWindowsErrorReportingCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180014EE8: "public: virtual void * __ptr64 __cdecl NtWin32LiveSystemProvider::`vector deleting destructor'(unsigned int) __ptr64" ??_ENtWin32LiveSystemProvider@@UEAAPEAXI@Z
0x180007A40: "public: virtual unsigned long __cdecl GenClrDataEnumMemoryRegionsCallback::AddRef(void) __ptr64" ?AddRef@GenClrDataEnumMemoryRegionsCallback@@UEAAKXZ
0x18000C440: "long __cdecl GenFilterContext(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_THREAD * __ptr64,void * __ptr64,unsigned long,unsigned char)" ?GenFilterContext@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_THREAD@@PEAXKE@Z
0x180005360: "long __cdecl MarshalExceptionPointers(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_EXCEPTION_INFORMATION64 const * __ptr64,struct _EXCEPTION_INFO * __ptr64)" ?MarshalExceptionPointers@@YAJPEAU_MINIDUMP_STATE@@PEBU_MINIDUMP_EXCEPTION_INFORMATION64@@PEAU_EXCEPTION_INFO@@@Z
0x18001C7A8: "WriteFullMemory.Desc.Write(0x%x)" ??_C@_0DA@NLHKLNPE@WriteFullMemory?4Desc?4Write?$CI0x?$CFx?$CJ@
0x18001EAF8: "StackWalk64" ??_C@_0M@FJINHFIC@StackWalk64?$AA@
0x18001D060: "api-ms-win-core-processsecurity-" ??_C@_0CH@BAEAFDKH@api?9ms?9win?9core?9processsecurity?9@
0x180023028: "__cdecl _memcpy_nt_iters" __memcpy_nt_iters
0x18001A394: "__cdecl wcsicmp" _wcsicmp
0x18001BC08: "__cdecl _imp__o_malloc" __imp__o_malloc
0x180009660: "public: virtual long __cdecl GenClrDataTarget::GetCurrentThreadID(unsigned int * __ptr64) __ptr64" ?GetCurrentThreadID@GenClrDataTarget@@UEAAJPEAI@Z
0x18001FD68: "PathFindFileNameW" ??_C@_0BC@LBBOIOOJ@PathFindFileNameW?$AA@
0x1800267F0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreIoCallsDesc" ?g_CoreIoCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001D980: "ThreadToken_Group(0x%08X,%d,%d,%" ??_C@_0CD@GACMPOEI@ThreadToken_Group?$CI0x?$CF08X?0?$CFd?0?$CFd?0?$CF@
0x18001CC58: "Invalid instruction window size " ??_C@_0CH@FLFPDFOC@Invalid?5instruction?5window?5size?5@
0x18001CE10: "Module32NextW" ??_C@_0O@NADNHHIC@Module32NextW?$AA@
0x18000B8AC: "int __cdecl GenExecuteIncludeModuleCallback(struct _MINIDUMP_STATE * __ptr64,unsigned __int64,unsigned long * __ptr64)" ?GenExecuteIncludeModuleCallback@@YAHPEAU_MINIDUMP_STATE@@_KPEAK@Z
0x18001A5C7: memcpy
0x180006A70: MiniDumpReadDumpStream
0x1800111F0: "public: virtual long __cdecl CallbackOutputProvider::Seek(unsigned long,__int64,unsigned __int64 * __ptr64) __ptr64" ?Seek@CallbackOutputProvider@@UEAAJK_JPEA_K@Z
0x1800011C8: "int __cdecl AddressInModule(struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned char)" ?AddressInModule@@YAHPEAU_INTERNAL_PROCESS@@_KE@Z
0x18001E310: "GenWriteHandleData.ObjectNameLen" ??_C@_0DM@EMCMHLOI@GenWriteHandleData?4ObjectNameLen@
0x18001BA38: "__cdecl _imp_LoadLibraryExW" __imp_LoadLibraryExW
0x180025E00: "struct _DYNAMIC_CALL_NAME volatile * volatile g_EventingProviderCallNames" ?g_EventingProviderCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180023640: RtlpMrdataSectionLockCount
0x18000D858: "void __cdecl GenAddModuleHeaders(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,struct _IMAGE_NT_HEADERS64 * __ptr64,void * __ptr64,unsigned short const * __ptr64)" ?GenAddModuleHeaders@@YAXPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@_KPEAU_IMAGE_NT_HEADERS64@@PEAXPEBG@Z
0x180011ABC: "long __cdecl GenAddOrExtendMemoryRange(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _VA_RANGE * __ptr64,unsigned __int64,unsigned __int64,enum MEMBLOCK_TYPE,enum MEMBLOCK_FILTER_TYPE)" ?GenAddOrExtendMemoryRange@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_VA_RANGE@@_K3W4MEMBLOCK_TYPE@@W4MEMBLOCK_FILTER_TYPE@@@Z
0x18001BC78: "__cdecl _imp_memset" __imp_memset
0x180025370: "struct _DOWNLEVEL_SHLWAPI_L1_CALLS volatile g_DownlevelShlwapiL1Calls" ?g_DownlevelShlwapiL1Calls@@3U_DOWNLEVEL_SHLWAPI_L1_CALLS@@C
0x18001A440: "__cdecl _acrt_initialize" __acrt_initialize
0x180002DD4: "long __cdecl WriteDirectoryEntry(struct _MINIDUMP_STATE * __ptr64,unsigned long,unsigned long,unsigned __int64)" ?WriteDirectoryEntry@@YAJPEAU_MINIDUMP_STATE@@KK_K@Z
0x18001E8B8: "NtSystemDebugControl" ??_C@_0BF@OAMAAEOC@NtSystemDebugControl?$AA@
0x18001F020: "NtResumeProcess" ??_C@_0BA@PNNBPCAM@NtResumeProcess?$AA@
0x18001A2F6: "__cdecl initterm" _initterm
0x18001E588: "__cdecl GUID_3e11ccee_d08b_43e5_af01_32717a64da03" _GUID_3e11ccee_d08b_43e5_af01_32717a64da03
0x1800254A0: "struct _CORE_TOOLHELP_CALLS volatile g_CoreToolHelpCalls" ?g_CoreToolHelpCalls@@3U_CORE_TOOLHELP_CALLS@@C
0x18001F678: "GetPackageApplicationIds" ??_C@_0BJ@IDNJBAAH@GetPackageApplicationIds?$AA@
0x180018F90: "public: virtual long __cdecl StackProviderDataTarget::GetStackTrace(unsigned long,struct _tagSTACKFRAME64 * __ptr64,void * __ptr64) __ptr64" ?GetStackTrace@StackProviderDataTarget@@UEAAJKPEAU_tagSTACKFRAME64@@PEAX@Z
0x18001FE10: "shlwapi.dll" ??_C@_0M@PPBCJOEJ@shlwapi?4dll?$AA@
0x18001A362: "__cdecl o__initialize_onexit_table" _o__initialize_onexit_table
0x180021A40: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x180023698: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x18001FB58: "CoUnmarshalInterface" ??_C@_0BF@JFFBDLH@CoUnmarshalInterface?$AA@
0x18001F958: "api-ms-win-core-comm-l1-1-0.dll" ??_C@_0CA@LJFACAML@api?9ms?9win?9core?9comm?9l1?91?90?4dll?$AA@
0x180025330: "struct _DOWNLEVEL_SHLWAPI_L2_CALLS volatile g_DownlevelShlwapiL2Calls" ?g_DownlevelShlwapiL2Calls@@3U_DOWNLEVEL_SHLWAPI_L2_CALLS@@C
0x180016780: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumHandleObjectInfo(unsigned __int64,unsigned short const * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?EnumHandleObjectInfo@NtWin32LiveSystemProvider@@UEAAJ_KPEBGKPEAKPEAXK2@Z
0x18001BAE0: "__cdecl _imp_Sleep" __imp_Sleep
0x18001E1B0: "GenGetProcessInfo.EnumFunctionTa" ??_C@_0DK@KEIFMIMH@GenGetProcessInfo?4EnumFunctionTa@
0x18001F340: "FileTimeToDosDateTime" ??_C@_0BG@KFDBAGBJ@FileTimeToDosDateTime?$AA@
0x18001BD08: "__cdecl _xi_z" __xi_z
0x18001CBE0: "Invalid page size (0x%x)" ??_C@_0BJ@CDDFDIIH@Invalid?5page?5size?5?$CI0x?$CFx?$CJ?$AA@
0x1800132F0: "public: virtual unsigned long __cdecl PssNtWin32LiveSystemProvider::ResumeThread(void * __ptr64) __ptr64" ?ResumeThread@PssNtWin32LiveSystemProvider@@UEAAKPEAX@Z
0x180025C50: "union _RTL_RUN_ONCE volatile g_RunOnceMrdataCommitObtained" ?g_RunOnceMrdataCommitObtained@@3T_RTL_RUN_ONCE@@C
0x18001E5F0: "GenAddMemoryRegion.QueryVirtual(" ??_C@_0DI@PIFCHDDK@GenAddMemoryRegion?4QueryVirtual?$CI@
0x18001D6A0: "__cdecl GUID_471c35b4_7c2f_4ef0_a945_00f8c38056f1" _GUID_471c35b4_7c2f_4ef0_a945_00f8c38056f1
0x18001B978: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x180013C20: "private: static long __cdecl PssNtWin32LiveSystemProvider::s_RtlQpdiQueryInformation(void * __ptr64,enum _PROCESSINFOCLASS,void * __ptr64,unsigned long,unsigned long * __ptr64)" ?s_RtlQpdiQueryInformation@PssNtWin32LiveSystemProvider@@CAJPEAXW4_PROCESSINFOCLASS@@0KPEAK@Z
0x180016270: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumUnloadedModules(unsigned short * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64) __ptr64" ?EnumUnloadedModules@NtWin32LiveSystemProvider@@UEAAJPEAGKPEA_KPEAK22@Z
0x18000F5A0: "public: virtual long __cdecl GenClrDataTarget::AllocVirtual(unsigned __int64,unsigned int,unsigned int,unsigned int,unsigned __int64 * __ptr64) __ptr64" ?AllocVirtual@GenClrDataTarget@@UEAAJ_KIIIPEA_K@Z
0x18001F3D0: "GetPrivateProfileStringW" ??_C@_0BJ@HLFNMLJD@GetPrivateProfileStringW?$AA@
0x180015B4C: "protected: long __cdecl NtWin32LiveSystemProvider::ReadUnloadTrace(void * __ptr64) __ptr64" ?ReadUnloadTrace@NtWin32LiveSystemProvider@@IEAAJPEAX@Z
0x18001A3D0: "__cdecl _C_specific_handler" __C_specific_handler
0x18001F2C0: "QueueUserWorkItem" ??_C@_0BC@LALMFEHO@QueueUserWorkItem?$AA@
0x18001BC38: "__cdecl _imp___stdio_common_vswprintf_s" __imp___stdio_common_vswprintf_s
0x18000F710: "public: virtual long __cdecl GenClrDataEnumMemoryRegionsCallback::QueryInterface(struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?QueryInterface@GenClrDataEnumMemoryRegionsCallback@@UEAAJAEBU_GUID@@PEAPEAX@Z
0x18001BB70: "__cdecl _imp_ReleaseSRWLockExclusive" __imp_ReleaseSRWLockExclusive
0x18000E334: "long __cdecl GenAllocateProcessObject(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64 * __ptr64)" ?GenAllocateProcessObject@@YAJPEAU_MINIDUMP_STATE@@PEAPEAU_INTERNAL_PROCESS@@@Z
0x1800143F0: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::StartHandleOperationsEnum(void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64,struct _AVRF_HANDLE_OPERATION * __ptr64 * __ptr64) __ptr64" ?StartHandleOperationsEnum@PssNtWin32LiveSystemProvider@@UEAAJPEAXKPEA_KPEAKPEAPEAU_AVRF_HANDLE_OPERATION@@@Z
0x180013670: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetThreadContext(void * __ptr64,void * __ptr64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64) __ptr64" ?GetThreadContext@PssNtWin32LiveSystemProvider@@UEAAJPEAX00KPEA_K11@Z
0x18001A440: "__cdecl _acrt_thread_detach" __acrt_thread_detach
0x180015310: "public: virtual long __cdecl NtWin32LiveSystemProvider::OpenThread(unsigned long,int,unsigned long,void * __ptr64 * __ptr64) __ptr64" ?OpenThread@NtWin32LiveSystemProvider@@UEAAJKHKPEAPEAX@Z
0x18001CAE0: "Invalid context size (0x%x)" ??_C@_0BM@DNNOHMNK@Invalid?5context?5size?5?$CI0x?$CFx?$CJ?$AA@
0x180023670: "protected: static unsigned long (__cdecl* __ptr64 Win32LiveSystemProvider::s_GetFileVersionInfoSizeExA)(unsigned long,char const * __ptr64,unsigned long * __ptr64)" ?s_GetFileVersionInfoSizeExA@Win32LiveSystemProvider@@1P6AKKPEBDPEAK@ZEA
0x18001F368: "GetComputerNameW" ??_C@_0BB@GFABHBEI@GetComputerNameW?$AA@
0x1800079F0: "public: virtual long __cdecl Win32LiveSystemProvider::QueryMiscInformation(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?QueryMiscInformation@Win32LiveSystemProvider@@UEAAJPEAXKPEAK0K1@Z
0x18001FBF0: "RoGetActivationFactory" ??_C@_0BH@ELDDNMMN@RoGetActivationFactory?$AA@
0x18001CFE0: "api-ms-win-core-kernel32-legacy-" ??_C@_0CL@MFCIFGNP@api?9ms?9win?9core?9kernel32?9legacy?9@
0x18001E138: "GenGetProcessInfo.EnumUnloadedMo" ??_C@_0DL@CACADBBM@GenGetProcessInfo?4EnumUnloadedMo@
0x18001A5D3: memmove
0x18001F698: "PackageIdFromFullName" ??_C@_0BG@MMKMBIJJ@PackageIdFromFullName?$AA@
0x180009840: "public: virtual long __cdecl Win32FileOutputProvider::SupportsStreaming(void) __ptr64" ?SupportsStreaming@Win32FileOutputProvider@@UEAAJXZ
0x18001B9F8: "__cdecl _imp_HeapFree" __imp_HeapFree
0x18001D278: "CurrentType" ??_C@_0M@CEKFLLMI@CurrentType?$AA@
0x180026140: "struct _DYNAMIC_CALL_NAME volatile * volatile g_WintrustCallNames" ?g_WintrustCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180025460: "struct _API_MS_WIN_CORE_COM_L1_CALLS volatile g_ApiMsWinCoreComL1Calls" ?g_ApiMsWinCoreComL1Calls@@3U_API_MS_WIN_CORE_COM_L1_CALLS@@C
0x180013910: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetPeb(void * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetPeb@PssNtWin32LiveSystemProvider@@UEAAJPEAXPEA_KPEAK@Z
0x180025BB0: "struct _SHLWAPI_CALLS volatile g_ShlWapiCalls" ?g_ShlWapiCalls@@3U_SHLWAPI_CALLS@@C
0x180013390: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetTeb(void * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetTeb@PssNtWin32LiveSystemProvider@@UEAAJPEAXPEA_KPEAK@Z
0x180019EEC: "__cdecl _scrt_uninitialize_crt" __scrt_uninitialize_crt
0x18001C670: "Memory info stream RVA overflowe" ??_C@_0CC@BKLLMKHB@Memory?5info?5stream?5RVA?5overflowe@
0x18001A3B8: malloc
0x180026420: "struct _DYNAMIC_CALL_NAME volatile * volatile g_ServiceCoreCallNames" ?g_ServiceCoreCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001DA00: "ThreadToken_Statistics(0x%08X,%d" ??_C@_0CI@EPIDJIIK@ThreadToken_Statistics?$CI0x?$CF08X?0?$CFd@
0x18001B9E0: api-ms-win-core-handle-l1-1-0_NULL_THUNK_DATA
0x18001FE70: "api-ms-win-downlevel-shlwapi-l2-" ??_C@_0CI@PMBPMFNE@api?9ms?9win?9downlevel?9shlwapi?9l2?9@
0x18001D828: "GenGetImageSections.Section.Read" ??_C@_0DP@HAFBDJLK@GenGetImageSections?4Section?4Read@
0x18001F118: "SetProcessShutdownParameters" ??_C@_0BN@OGPGPIEJ@SetProcessShutdownParameters?$AA@
0x18000F340: "public: virtual long __cdecl GenClrDataTarget::GetPointerSize(unsigned int * __ptr64) __ptr64" ?GetPointerSize@GenClrDataTarget@@UEAAJPEAI@Z
0x180008900: "private: long __cdecl Win32LiveSystemProvider::GetXStateContext(void * __ptr64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64) __ptr64" ?GetXStateContext@Win32LiveSystemProvider@@AEAAJPEAX0KPEA_K11@Z
0x18001BBF8: "__cdecl _imp__o__wsplitpath_s" __imp__o__wsplitpath_s
0x18001E2D8: "GenWriteHandleData.TypeName.Writ" ??_C@_0DH@GOOCEOHD@GenWriteHandleData?4TypeName?4Writ@
0x18001BA90: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x18001D700: "Thread(0x%x) will not be include" ??_C@_0CC@NPPCIDOK@Thread?$CI0x?$CFx?$CJ?5will?5not?5be?5include@
0x18001A470: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x18001D158: "BaseSetLastNTError" ??_C@_0BD@DBIPMLDN@BaseSetLastNTError?$AA@
0x18001F780: "userenv.dll" ??_C@_0M@GKFBEPIE@userenv?4dll?$AA@
0x18001A31A: "__cdecl o___std_type_info_destroy_list" _o___std_type_info_destroy_list
0x18001F808: "GetProcessId" ??_C@_0N@PLLAIOPL@GetProcessId?$AA@
0x180026910: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreSynchCallNames" ?g_CoreSynchCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180019E20: "__cdecl _scrt_is_nonwritable_in_current_image" __scrt_is_nonwritable_in_current_image
0x180020118: "GetNumberOfEventLogRecords" ??_C@_0BL@HLAMFCHD@GetNumberOfEventLogRecords?$AA@
0x1800254E0: "struct _KERNEL32_CALLS volatile g_Kernel32Calls" ?g_Kernel32Calls@@3U_KERNEL32_CALLS@@C
0x18001E848: "NtOpenThread" ??_C@_0N@EJDHLIH@NtOpenThread?$AA@
0x18001FA60: "PrivateKDBreakPoint" ??_C@_0BE@CIDEACDK@PrivateKDBreakPoint?$AA@
0x18001FFA8: "CertOpenSystemStoreA" ??_C@_0BF@LOBCDGKG@CertOpenSystemStoreA?$AA@
0x18001FC80: "SysFreeString" ??_C@_0O@HGGCANLK@SysFreeString?$AA@
0x18001A332: "__cdecl cexit" _cexit
0x18001A3AC: "__cdecl o_free" _o_free
0x18001DFA0: "GenInvokeEnumStackProviders(%ws)" ??_C@_0DA@PIBKKPJN@GenInvokeEnumStackProviders?$CI?$CFws?$CJ@
0x180019CF0: "__cdecl _scrt_initialize_crt" __scrt_initialize_crt
0x18001EFB8: "RtlSetLastWin32ErrorAndNtStatusF" ??_C@_0CM@HHACLIG@RtlSetLastWin32ErrorAndNtStatusF@
0x18001FEB8: "CertCloseStore" ??_C@_0P@FADIKHJH@CertCloseStore?$AA@
0x18001F528: "GetCommState" ??_C@_0N@NHAHINCA@GetCommState?$AA@
0x180020008: "CryptAcquireCertificatePrivateKe" ??_C@_0CC@JGCNJPGL@CryptAcquireCertificatePrivateKe@
0x180020278: "CryptGetHashParam" ??_C@_0BC@BNEOPJAJ@CryptGetHashParam?$AA@
0x180020048: "ControlService" ??_C@_0P@OACFAAAJ@ControlService?$AA@
0x18001A440: "__cdecl _acrt_uninitialize" __acrt_uninitialize
0x18001BC80: api-ms-win-crt-string-l1-1-0_NULL_THUNK_DATA
0x18001A34A: "__cdecl o__execute_onexit_table" _o__execute_onexit_table
0x18001DC50: "GenAllocateModuleObject.GetImage" ??_C@_0EI@BPDEANFJ@GenAllocateModuleObject?4GetImage@
0x1800200B8: "BackupEventLogA" ??_C@_0BA@GILFMDNH@BackupEventLogA?$AA@
0x180019B18: "void __cdecl __scrt_uninitialize_type_info(void)" ?__scrt_uninitialize_type_info@@YAXXZ
0x18001E9C0: "NtQuerySemaphore" ??_C@_0BB@IKGLGKED@NtQuerySemaphore?$AA@
0x18001BAF0: api-ms-win-core-misc-l1-1-0_NULL_THUNK_DATA
0x18001FDA8: "PathIsUNCServerW" ??_C@_0BB@EDOLCPKD@PathIsUNCServerW?$AA@
0x18001BB60: api-ms-win-core-string-l1-1-0_NULL_THUNK_DATA
0x1800123D8: "void __cdecl GenRemoveMemoryRange(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned long)" ?GenRemoveMemoryRange@@YAXPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@_KK@Z
0x1800202C8: "EventUnregister" ??_C@_0BA@FAKLIPIC@EventUnregister?$AA@
0x18001D288: "checked" ??_C@_07FJOBMBFC@checked?$AA@
0x1800201D0: "OpenServiceA" ??_C@_0N@MPAGLEEC@OpenServiceA?$AA@
0x18001F408: "SwitchToFiber" ??_C@_0O@LHEJOJMP@SwitchToFiber?$AA@
0x1800017E0: "long __cdecl WriteAtOffset(struct _MINIDUMP_STATE * __ptr64,unsigned long,void * __ptr64,unsigned long)" ?WriteAtOffset@@YAJPEAU_MINIDUMP_STATE@@KPEAXK@Z
0x18001C820: "WriteFullMemory.Memory.Read(0x%I" ??_C@_0EA@JDFJAEEP@WriteFullMemory?4Memory?4Read?$CI0x?$CFI@
0x1800253F0: "struct _DOWNLEVEL_KERNEL32_L2_CALLS volatile g_DownlevelKernel32L2Calls" ?g_DownlevelKernel32L2Calls@@3U_DOWNLEVEL_KERNEL32_L2_CALLS@@C
0x180025490: "struct _CORE_PROCESS_SECURITY_CALLS volatile g_CoreProcessSecurityCalls" ?g_CoreProcessSecurityCalls@@3U_CORE_PROCESS_SECURITY_CALLS@@C
0x1800088E0: "public: virtual unsigned long __cdecl Win32LiveSystemProvider::SuspendThread(void * __ptr64) __ptr64" ?SuspendThread@Win32LiveSystemProvider@@UEAAKPEAX@Z
0x180025350: "struct _CORE_PROCESSENVIRONMENT_CALLS volatile g_CoreProcessEnvironmentCalls" ?g_CoreProcessEnvironmentCalls@@3U_CORE_PROCESSENVIRONMENT_CALLS@@C
0x1800041A4: "long __cdecl WriteException(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _EXCEPTION_INFO * __ptr64 const)" ?WriteException@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@QEAU_EXCEPTION_INFO@@@Z
0x18001EA40: "GetSidSubAuthorityCount" ??_C@_0BI@LPFJALDI@GetSidSubAuthorityCount?$AA@
0x180026520: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreMiscCallNames" ?g_CoreMiscCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180021A2C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-misc-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-misc-l1-1-0
0x1800164C0: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumHandles(unsigned __int64 * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned short * __ptr64,unsigned long,unsigned short * __ptr64,unsigned long) __ptr64" ?EnumHandles@NtWin32LiveSystemProvider@@UEAAJPEA_KPEAK111PEAGK2K@Z
0x180025180: "struct _CORE_DEBUG_CALLS volatile g_CoreDebugCalls" ?g_CoreDebugCalls@@3U_CORE_DEBUG_CALLS@@C
0x180025938: "struct _CORE_PSAPI_CALLS volatile g_CorePsapiCalls" ?g_CorePsapiCalls@@3U_CORE_PSAPI_CALLS@@C
0x180025C08: "struct _CORE_SYNCH_CALLS volatile g_CoreSynchCalls" ?g_CoreSynchCalls@@3U_CORE_SYNCH_CALLS@@C
0x180025090: "struct _CORE_WINDOWSERRORREPORTING_CALLS volatile g_CoreWindowsErrorReportingCalls" ?g_CoreWindowsErrorReportingCalls@@3U_CORE_WINDOWSERRORREPORTING_CALLS@@C
0x18001E6E0: "PssWalkMarkerCreate" ??_C@_0BE@HAENKGPJ@PssWalkMarkerCreate?$AA@
0x180012620: "public: virtual void * __ptr64 __cdecl PssNtWin32LiveSystemProvider::`vector deleting destructor'(unsigned int) __ptr64" ??_EPssNtWin32LiveSystemProvider@@UEAAPEAXI@Z
0x180027130: "struct _DYNAMIC_CALLS_DESC volatile g_CoreProcessSecurityCallsDesc" ?g_CoreProcessSecurityCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180007A40: "public: virtual long __cdecl Win32LiveSystemProvider::EnumFunctionTables(unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64,void * __ptr64,unsigned long,void * __ptr64 * __ptr64,class MiniDumpProviderCallbacks * __ptr64) __ptr64" ?EnumFunctionTables@Win32LiveSystemProvider@@UEAAJPEA_K00PEAKPEAXKPEAPEAXPEAVMiniDumpProviderCallbacks@@@Z
0x18000B400: "public: virtual long __cdecl StackProviderDataTarget::QueryInterface(struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?QueryInterface@StackProviderDataTarget@@UEAAJAEBU_GUID@@PEAPEAX@Z
0x1800250D0: "struct _SSPICLI_CALLS volatile g_SspiCliCalls" ?g_SspiCliCalls@@3U_SSPICLI_CALLS@@C
0x180026240: "struct _DYNAMIC_CALLS_DESC volatile g_DownlevelKernel32L1CallsDesc" ?g_DownlevelKernel32L1CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180002394: "long __cdecl WriteFunctionTableList(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteFunctionTableList@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x18001E900: "RtlGetUnloadEventTrace" ??_C@_0BH@BEBBGBAE@RtlGetUnloadEventTrace?$AA@
0x180020358: "api-ms-win-eventlog-legacy-l1-1-" ??_C@_0CG@NJEPIBIM@api?9ms?9win?9eventlog?9legacy?9l1?91?9@
0x180020030: "CloseServiceHandle" ??_C@_0BD@DLOBKKPI@CloseServiceHandle?$AA@
0x180009840: "public: virtual long __cdecl Win32LiveSystemProvider::EnumTebMemory(void * __ptr64,void * __ptr64,unsigned long,unsigned __int64,unsigned long,class MiniDumpProviderCallbacks * __ptr64) __ptr64" ?EnumTebMemory@Win32LiveSystemProvider@@UEAAJPEAX0K_KKPEAVMiniDumpProviderCallbacks@@@Z
0x18001A440: "__cdecl _scrt_stub_for_acrt_thread_detach" __scrt_stub_for_acrt_thread_detach
0x18000C674: "bool __cdecl VerifyMapping(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned short * __ptr64,void * __ptr64,unsigned __int64,unsigned __int64)" ?VerifyMapping@@YA_NPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAGPEAX_K4@Z
0x18000F96C: "long __cdecl IncrementHandleData(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,int)" ?IncrementHandleData@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@H@Z
0x1800091E0: "public: virtual long __cdecl Win32LiveSystemProvider::StartProcessEnum(void * __ptr64,unsigned long) __ptr64" ?StartProcessEnum@Win32LiveSystemProvider@@UEAAJPEAXK@Z
0x18001FBA8: "ole32.dll" ??_C@_09IMMMOKKM@ole32?4dll?$AA@
0x1800185F4: "public: __cdecl RtlMrdataObtainSectionWriteAccess::~RtlMrdataObtainSectionWriteAccess(void) __ptr64" ??1RtlMrdataObtainSectionWriteAccess@@QEAA@XZ
0x18001EFE8: "RtlSetExtendedFeaturesMask" ??_C@_0BL@ELHCBNPD@RtlSetExtendedFeaturesMask?$AA@
0x18001EAD0: "File" ??_C@_19DDLLJDOO@?$AAF?$AAi?$AAl?$AAe?$AA?$AA@
0x18001CEF0: "GetCachedSigningLevel" ??_C@_0BG@NDMEFAJE@GetCachedSigningLevel?$AA@
0x18001C9F8: "Kernel minidump write failed, 0x" ??_C@_0CF@GHIJFMBK@Kernel?5minidump?5write?5failed?0?50x@
0x18001E9E8: "advapi32.dll" ??_C@_0N@INAGJMNN@advapi32?4dll?$AA@
0x18001F278: "CreateSemaphoreExW" ??_C@_0BD@KIEEOEEH@CreateSemaphoreExW?$AA@
0x18000A690: "public: virtual long __cdecl Win32LiveSystemProvider::QuerySystemMemoryInformation(struct _MINIDUMP_SYSTEM_MEMORY_INFO_1 * __ptr64,unsigned long) __ptr64" ?QuerySystemMemoryInformation@Win32LiveSystemProvider@@UEAAJPEAU_MINIDUMP_SYSTEM_MEMORY_INFO_1@@K@Z
0x180019C9C: "__cdecl _scrt_dllmain_uninitialize_c" __scrt_dllmain_uninitialize_c
0x180009840: "public: virtual long __cdecl Win32FileOutputProvider::Start(unsigned __int64) __ptr64" ?Start@Win32FileOutputProvider@@UEAAJ_K@Z
0x1800251F0: "struct _MPR_CALLS volatile g_MprCalls" ?g_MprCalls@@3U_MPR_CALLS@@C
0x18001DB38: "Unable to add module "%ws" PE he" ??_C@_0DO@PAFCJNMM@Unable?5to?5add?5module?5?$CC?$CFws?$CC?5PE?5he@
0x18001BAE8: "__cdecl _imp_lstrcmpiW" __imp_lstrcmpiW
0x18001F5E0: "QueryInformationJobObject" ??_C@_0BK@DNBGKNHH@QueryInformationJobObject?$AA@
0x18001F0F0: "Process32NextW" ??_C@_0P@HGJPNFAI@Process32NextW?$AA@
0x18001BB50: "__cdecl _imp_WideCharToMultiByte" __imp_WideCharToMultiByte
0x18001C720: "Full memory stream RVA overflowe" ??_C@_0CC@PCJAKJDN@Full?5memory?5stream?5RVA?5overflowe@
0x18001BBD0: "__cdecl _imp__o__purecall" __imp__o__purecall
0x18001E688: "api-ms-win-core-processsnapshot-" ??_C@_0CL@IOHLEPGJ@api?9ms?9win?9core?9processsnapshot?9@
0x18001B268: "const Win32FileOutputProvider::`vftable'" ??_7Win32FileOutputProvider@@6B@
0x180026700: "struct _DYNAMIC_CALLS_DESC volatile g_CoreRegistryPrivateCallsDesc" ?g_CoreRegistryPrivateCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18000984C: "private: long __cdecl Win32LiveSystemProvider::GetAuxiliaryProviderFromImageResource(struct HINSTANCE__ * __ptr64,unsigned short const * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?GetAuxiliaryProviderFromImageResource@Win32LiveSystemProvider@@AEAAJPEAUHINSTANCE__@@PEBGPEAGK@Z
0x1800173D0: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetOsCsdString(unsigned short * __ptr64,unsigned long) __ptr64" ?GetOsCsdString@NtWin32LiveSystemProvider@@UEAAJPEAGK@Z
0x18001A356: "__cdecl o__initialize_narrow_environment" _o__initialize_narrow_environment
0x18000C4A8: "long __cdecl GenGetDebugRecord(struct _MINIDUMP_STATE * __ptr64,void * __ptr64,unsigned long,unsigned long,unsigned long,void * __ptr64 * __ptr64,unsigned long * __ptr64)" ?GenGetDebugRecord@@YAJPEAU_MINIDUMP_STATE@@PEAXKKKPEAPEAXPEAK@Z
0x18001F250: "GetCommandLineW" ??_C@_0BA@NKEGPFCL@GetCommandLineW?$AA@
0x18001E100: "GenGetProcessInfo.EnumUnloadedMo" ??_C@_0DD@HNIKLAAL@GenGetProcessInfo?4EnumUnloadedMo@
0x18001BA50: "__cdecl _imp_LoadLibraryExA" __imp_LoadLibraryExA
0x18001BC10: "__cdecl _imp_towlower" __imp_towlower
0x1800201C0: "OpenSCManagerW" ??_C@_0P@LEIGFCJD@OpenSCManagerW?$AA@
0x180026050: "struct _DYNAMIC_CALLS_DESC volatile g_ShlwapiIeCallsDesc" ?g_ShlwapiIeCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001E760: "PssWalkMarkerSetPosition" ??_C@_0BJ@PIAHPPMK@PssWalkMarkerSetPosition?$AA@
0x18001CF58: "kernelbase.dll" ??_C@_0P@OEFGOMJK@kernelbase?4dll?$AA@
0x18001D230: "BuildLabEx" ??_C@_1BG@CLMGIAOK@?$AAB?$AAu?$AAi?$AAl?$AAd?$AAL?$AAa?$AAb?$AAE?$AAx?$AA?$AA@
0x18001CB70: "AMD64" ??_C@_1M@EEBFAJEO@?$AAA?$AAM?$AAD?$AA6?$AA4?$AA?$AA@
0x1800137D0: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetThreadOsInfo(void * __ptr64,void * __ptr64,struct _UMINIPROV_THREAD_INFO * __ptr64) __ptr64" ?GetThreadOsInfo@PssNtWin32LiveSystemProvider@@UEAAJPEAX0PEAU_UMINIPROV_THREAD_INFO@@@Z
0x18001A3A0: "__cdecl o__wsplitpath_s" _o__wsplitpath_s
0x18001ECC0: "DbgUiIssueRemoteBreakin" ??_C@_0BI@JNIDGPMA@DbgUiIssueRemoteBreakin?$AA@
0x1800275D0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreFileL1CallsDesc" ?g_CoreFileL1CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180026350: "struct _DYNAMIC_CALLS_DESC volatile g_CoreFileL2CallsDesc" ?g_CoreFileL2CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180013C60: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::EnumModules(unsigned __int64 * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?EnumModules@PssNtWin32LiveSystemProvider@@UEAAJPEA_KPEAGK@Z
0x18001FE00: "PathFileExistsW" ??_C@_0BA@MGGAPBAJ@PathFileExistsW?$AA@
0x180010F5C: "long __cdecl GenWriteHandleOperations(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?GenWriteHandleOperations@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x18001C378: "WriteTokenInformation.ProcessTok" ??_C@_0DJ@IEKHNMJE@WriteTokenInformation?4ProcessTok@
0x180009670: "public: virtual void __cdecl Win32LiveSystemProvider::FinishProcessEnum(void) __ptr64" ?FinishProcessEnum@Win32LiveSystemProvider@@UEAAXXZ
0x18001E520: "GenWriteHandleOperations.Ops.Wri" ??_C@_0DI@NOMDDBBC@GenWriteHandleOperations?4Ops?4Wri@
0x180018900: "unsigned __int64 __cdecl GetModuleBaseProc64(void * __ptr64,unsigned __int64)" ?GetModuleBaseProc64@@YA_KPEAX_K@Z
0x18001A440: "__cdecl _scrt_stub_for_acrt_initialize" __scrt_stub_for_acrt_initialize
0x18001B998: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x180026000: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreDebugCallNames" ?g_CoreDebugCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180020380: "api-ms-win-core-processsecurity-" ??_C@_0CL@KMMDHOMM@api?9ms?9win?9core?9processsecurity?9@
0x18001F818: "api-ms-win-core-synch-l1-2-0.dll" ??_C@_0CB@DPNHNCCP@api?9ms?9win?9core?9synch?9l1?92?90?4dll@
0x18001BBD8: "__cdecl _imp__o__seh_filter_dll" __imp__o__seh_filter_dll
0x18001EC48: "DbgBreakPoint" ??_C@_0O@ODHAJHCA@DbgBreakPoint?$AA@
0x18001D640: "GetFileVersionInfoSizeA" ??_C@_0BI@FKDAHLLJ@GetFileVersionInfoSizeA?$AA@
0x18001D388: "CertVerifyCertificateChainPolicy" ??_C@_0CB@COAIKGLK@CertVerifyCertificateChainPolicy@
0x18001E0C8: "GenGetProcessInfo.EnumModules(0x" ??_C@_0DD@BACAOOAJ@GenGetProcessInfo?4EnumModules?$CI0x@
0x18001BAD0: "__cdecl _imp_VirtualFree" __imp_VirtualFree
0x18001BD20: "__cdecl _xt_a" __xt_a
0x18001F510: "GetCommModemStatus" ??_C@_0BD@CJOLMEPC@GetCommModemStatus?$AA@
0x180023634: "__cdecl _scrt_debugger_hook_flag" __scrt_debugger_hook_flag
0x18001FB18: "CoMarshalInterThreadInterfaceInS" ??_C@_0CG@DNMFLAOH@CoMarshalInterThreadInterfaceInS@
0x180020328: "api-ms-win-service-management-l1" ??_C@_0CJ@JGDAGPDJ@api?9ms?9win?9service?9management?9l1@
0x18001BB98: "__cdecl _imp_GetSystemInfo" __imp_GetSystemInfo
0x18001BB20: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x18001FF20: "CertFreeCertificateContext" ??_C@_0BL@PJJPAKMH@CertFreeCertificateContext?$AA@
0x180026930: "struct _DYNAMIC_CALLS_DESC volatile g_SecurityCryptoapiCallsDesc" ?g_SecurityCryptoapiCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001F220: "UnregisterApplicationRestart" ??_C@_0BN@MMANHJJL@UnregisterApplicationRestart?$AA@
0x18001BBD8: "__cdecl _imp__seh_filter_dll" __imp__seh_filter_dll
0x18001FCF8: "SafeArrayGetVartype" ??_C@_0BE@NMOKCKEI@SafeArrayGetVartype?$AA@
0x180020210: "RegConnectRegistryExW" ??_C@_0BG@KMOPACEK@RegConnectRegistryExW?$AA@
0x1800254D8: "struct _SERVICE_CORE_CALLS volatile g_ServiceCoreCalls" ?g_ServiceCoreCalls@@3U_SERVICE_CORE_CALLS@@C
0x18001FFF0: "CryptStringToBinaryA" ??_C@_0BF@LIGABANN@CryptStringToBinaryA?$AA@
0x1800202E8: "QueryServiceStatusEx" ??_C@_0BF@CLFHMDKP@QueryServiceStatusEx?$AA@
0x180008830: "public: virtual long __cdecl Win32LiveSystemProvider::GetImageDebugRecord(void * __ptr64,unsigned short const * __ptr64,unsigned __int64,unsigned long,void * __ptr64,unsigned long * __ptr64) __ptr64" ?GetImageDebugRecord@Win32LiveSystemProvider@@UEAAJPEAXPEBG_KK0PEAK@Z
0x18001F648: "GetProcessImageFileNameW" ??_C@_0BJ@FEKDIPFC@GetProcessImageFileNameW?$AA@
0x1800267C0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_SecurityBaseCallNames" ?g_SecurityBaseCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180020170: "RegisterEventSourceA" ??_C@_0BF@EBHPDBGP@RegisterEventSourceA?$AA@
0x18001E800: "Process" ??_C@_1BA@NMDNJJOO@?$AAP?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?$AA@
0x18001D750: "Dump generation cancelled by Can" ??_C@_0CM@PAIJBOFL@Dump?5generation?5cancelled?5by?5Can@
0x180019AD8: DllMain
0x18001F3F0: "SetConsoleTitleW" ??_C@_0BB@GOMIMMPM@SetConsoleTitleW?$AA@
0x180027190: "struct _DYNAMIC_CALL_NAME volatile * volatile g_Advapi32CallNames" ?g_Advapi32CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180025C68: "struct _DYNAMIC_CALL_NAME volatile * volatile g_ExtMsWinKernel32PackageL1_1_1CallNames" ?g_ExtMsWinKernel32PackageL1_1_1CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001A440: "__cdecl _scrt_stub_for_acrt_thread_attach" __scrt_stub_for_acrt_thread_attach
0x180012A80: "public: virtual void __cdecl PssNtWin32LiveSystemProvider::GetContextSizesEx(unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long) __ptr64" ?GetContextSizesEx@PssNtWin32LiveSystemProvider@@UEAAXPEAK00K@Z
0x18001F1D0: "SearchPathW" ??_C@_0M@BHLOJKBL@SearchPathW?$AA@
0x180012B10: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::ReadVirtual(void * __ptr64,unsigned __int64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?ReadVirtual@PssNtWin32LiveSystemProvider@@UEAAJPEAX_K0KPEAK@Z
0x180013260: "public: virtual unsigned long __cdecl PssNtWin32LiveSystemProvider::SuspendThread(void * __ptr64) __ptr64" ?SuspendThread@PssNtWin32LiveSystemProvider@@UEAAKPEAX@Z
0x18000E258: "long __cdecl GenAllocateFunctionTableObject(struct _MINIDUMP_STATE * __ptr64,unsigned __int64,unsigned __int64,unsigned __int64,unsigned long,void * __ptr64,struct _INTERNAL_FUNCTION_TABLE * __ptr64 * __ptr64)" ?GenAllocateFunctionTableObject@@YAJPEAU_MINIDUMP_STATE@@_K11KPEAXPEAPEAU_INTERNAL_FUNCTION_TABLE@@@Z
0x180026990: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreCommCallNames" ?g_CoreCommCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180018C40: "public: virtual long __cdecl StackProviderDataTarget::GetModuleByModuleName(unsigned short const * __ptr64,unsigned __int64 * __ptr64) __ptr64" ?GetModuleByModuleName@StackProviderDataTarget@@UEAAJPEBGPEA_K@Z
0x18001A0D8: "__cdecl RTC_Terminate" _RTC_Terminate
0x18001BA68: api-ms-win-core-libraryloader-l1-1-0_NULL_THUNK_DATA
0x180018BF0: "public: virtual long __cdecl StackProviderDataTarget::ReadVirtual(unsigned __int64,unsigned char * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?ReadVirtual@StackProviderDataTarget@@UEAAJ_KPEAEKPEAK@Z
0x18001A4D4: "__cdecl _GSHandlerCheck_SEH" __GSHandlerCheck_SEH
0x1800251E8: "struct _USERENV_CALLS volatile g_UserEnvCalls" ?g_UserEnvCalls@@3U_USERENV_CALLS@@C
0x180021AB8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-string-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-string-l1-1-0
0x18001BBF0: "__cdecl _imp__wcsicmp" __imp__wcsicmp
0x18001F048: "CloseProfileUserMapping" ??_C@_0BI@EJCIIOIC@CloseProfileUserMapping?$AA@
0x18001BC30: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x180009840: "public: virtual long __cdecl Win32FileOutputProvider::Finish(void) __ptr64" ?Finish@Win32FileOutputProvider@@UEAAJXZ
0x180027010: "struct _DYNAMIC_CALLS_DESC volatile g_UserEnvCallsDesc" ?g_UserEnvCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001BB28: "__cdecl _imp_ResumeThread" __imp_ResumeThread
0x18001BC88: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x18001D378: "crypt32.dll" ??_C@_0M@DNEEGAAA@crypt32?4dll?$AA@
0x180007A40: "public: virtual unsigned long __cdecl StackProviderDataTarget::AddRef(void) __ptr64" ?AddRef@StackProviderDataTarget@@UEAAKXZ
0x180027450: "struct _DYNAMIC_CALLS_DESC volatile g_DownlevelShlwapiL2CallsDesc" ?g_DownlevelShlwapiL2CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180027CC0: "struct _DYNAMIC_CALLS_DESC volatile g_DownlevelShlwapiL1CallsDesc" ?g_DownlevelShlwapiL1CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001BC20: "__cdecl _imp_strstr" __imp_strstr
0x180005564: "long __cdecl GetExceptionInfo(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_EXCEPTION_INFORMATION64 const * __ptr64,struct _EXCEPTION_INFO * __ptr64 * __ptr64)" ?GetExceptionInfo@@YAJPEAU_MINIDUMP_STATE@@PEBU_MINIDUMP_EXCEPTION_INFORMATION64@@PEAPEAU_EXCEPTION_INFO@@@Z
0x180021A18: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-1-0
0x18000B200: "public: virtual void __cdecl NullStatusProvider::Release(void) __ptr64" ?Release@NullStatusProvider@@UEAAXXZ
0x180013D70: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::StartHandleEnum(void * __ptr64,unsigned long * __ptr64) __ptr64" ?StartHandleEnum@PssNtWin32LiveSystemProvider@@UEAAJPEAXPEAK@Z
0x18001D4E8: "verifier.dll" ??_C@_0N@OMFOKOFM@verifier?4dll?$AA@
0x180020290: "CryptHashData" ??_C@_0O@DAIMODJH@CryptHashData?$AA@
0x1800266D0: "struct _DYNAMIC_CALLS_DESC volatile g_VersionCallsDesc" ?g_VersionCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x1800121B4: "long __cdecl GenAddMemoryRegion(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,enum MEMBLOCK_TYPE,enum MEMBLOCK_FILTER_TYPE,unsigned __int64,unsigned __int64,unsigned long,unsigned long,unsigned __int64 * __ptr64)" ?GenAddMemoryRegion@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@W4MEMBLOCK_TYPE@@W4MEMBLOCK_FILTER_TYPE@@_K4KKPEA_K@Z
0x1800026CC: "long __cdecl CalculateSizeForThreads(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?CalculateSizeForThreads@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x18001D5E8: "version.dll" ??_C@_0M@JHNIIDCD@version?4dll?$AA@
0x180016380: "public: virtual long __cdecl NtWin32LiveSystemProvider::StartHandleEnum(void * __ptr64,unsigned long * __ptr64) __ptr64" ?StartHandleEnum@NtWin32LiveSystemProvider@@UEAAJPEAXPEAK@Z
0x18001B980: "__cdecl _imp_GetLastError" __imp_GetLastError
0x18001ECA0: "DbgUiGetThreadDebugObject" ??_C@_0BK@MFJEAHAM@DbgUiGetThreadDebugObject?$AA@
0x18001B9D8: "__cdecl _imp_DuplicateHandle" __imp_DuplicateHandle
0x180009660: "public: virtual long __cdecl GenClrDataTarget::GetTLSValue(unsigned int,unsigned int,unsigned __int64 * __ptr64) __ptr64" ?GetTLSValue@GenClrDataTarget@@UEAAJIIPEA_K@Z
0x18001FBD8: "RoActivateInstance" ??_C@_0BD@HNHPAIIG@RoActivateInstance?$AA@
0x180002F50: "long __cdecl AddIndirectMemory(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned long)" ?AddIndirectMemory@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@_KK@Z
0x18001D010: "api-ms-win-security-base-l1-2-0." ??_C@_0CE@PDMLOHN@api?9ms?9win?9security?9base?9l1?92?90?4@
0x18001F4F0: "ClearCommError" ??_C@_0P@EHAMOMJH@ClearCommError?$AA@
0x1800148D0: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::QueryProcessVmCounters(void * __ptr64,struct _MINIDUMP_PROCESS_VM_COUNTERS_2 * __ptr64,unsigned long) __ptr64" ?QueryProcessVmCounters@PssNtWin32LiveSystemProvider@@UEAAJPEAXPEAU_MINIDUMP_PROCESS_VM_COUNTERS_2@@K@Z
0x18001A44C: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x18001FF40: "CertGetCertificateChain" ??_C@_0BI@OILJBKCI@CertGetCertificateChain?$AA@
0x1800083D0: "public: virtual void __cdecl Win32LiveSystemProvider::CloseMapping(void * __ptr64) __ptr64" ?CloseMapping@Win32LiveSystemProvider@@UEAAXPEAX@Z
0x18001EBA8: "CreateFileMappingA" ??_C@_0BD@GJENCGJD@CreateFileMappingA?$AA@
0x180007A50: "public: virtual long __cdecl Win32LiveSystemProvider::QueryBuildString(unsigned short * __ptr64,unsigned long) __ptr64" ?QueryBuildString@Win32LiveSystemProvider@@UEAAJPEAGK@Z
0x180008D30: "public: virtual long __cdecl Win32LiveSystemProvider::ReadVirtual(void * __ptr64,unsigned __int64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?ReadVirtual@Win32LiveSystemProvider@@UEAAJPEAX_K0KPEAK@Z
0x180011958: "struct _VA_RANGE_REF * __ptr64 __cdecl GenFreeMemoryBlock(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _VA_RANGE * __ptr64,unsigned char)" ?GenFreeMemoryBlock@@YAPEAU_VA_RANGE_REF@@PEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_VA_RANGE@@E@Z
0x18001A356: "__cdecl initialize_narrow_environment" _initialize_narrow_environment
0x180012A60: "public: virtual void __cdecl PssNtWin32LiveSystemProvider::GetContextSizes(unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64) __ptr64" ?GetContextSizes@PssNtWin32LiveSystemProvider@@UEAAXPEAK00@Z
0x180023648: RtlpMrdataProtectionLock
0x18001FF98: "CertOpenStore" ??_C@_0O@PAKIPNAF@CertOpenStore?$AA@
0x18001D298: "syswow64" ??_C@_1BC@FENIHGII@?$AAs?$AAy?$AAs?$AAw?$AAo?$AAw?$AA6?$AA4?$AA?$AA@
0x18001C288: "WriteFunctionTableList.DumpTable" ??_C@_0DM@GHMEGFOH@WriteFunctionTableList?4DumpTable@
0x180014CE0: "private: static void __cdecl PssNtWin32LiveSystemProvider::PssFreeRoutine(void * __ptr64,void * __ptr64)" ?PssFreeRoutine@PssNtWin32LiveSystemProvider@@CAXPEAX0@Z
0x18000F5C0: "public: virtual long __cdecl GenClrDataTarget::GetExceptionRecord(unsigned int,unsigned int * __ptr64,unsigned char * __ptr64) __ptr64" ?GetExceptionRecord@GenClrDataTarget@@UEAAJIPEAIPEAE@Z
0x180001F1C: "long __cdecl WriteThreadInfoList(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteThreadInfoList@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x18001EC38: "CsrGetProcessId" ??_C@_0BA@DOJAGBJ@CsrGetProcessId?$AA@
0x18001C538: "WriteSystemInfo.GetOsCsdString f" ??_C@_0CO@LKAKHMIA@WriteSystemInfo?4GetOsCsdString?5f@
0x18001F538: "GetCommTimeouts" ??_C@_0BA@OFEKGFFN@GetCommTimeouts?$AA@
0x18001BCA8: "__cdecl _imp_NtDeviceIoControlFile" __imp_NtDeviceIoControlFile
0x18001DDF8: "ProcessToken_User(0x%08X,%d,%d,%" ??_C@_0CD@IEKAOAFI@ProcessToken_User?$CI0x?$CF08X?0?$CFd?0?$CFd?0?$CF@
0x18001CF20: "GetEnabledXStateFeatures" ??_C@_0BJ@DIBIJBHA@GetEnabledXStateFeatures?$AA@
0x180001298: "unsigned long __cdecl ScanMemoryForModuleRefs(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,int,unsigned __int64,unsigned long,void * __ptr64,enum MEMBLOCK_TYPE,enum MEMBLOCK_FILTER_TYPE,unsigned long,struct _VA_RANGE_REF * __ptr64)" ?ScanMemoryForModuleRefs@@YAKPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@H_KKPEAXW4MEMBLOCK_TYPE@@W4MEMBLOCK_FILTER_TYPE@@KPEAU_VA_RANGE_REF@@@Z
0x180023024: "__cdecl _isa_enabled" __isa_enabled
0x1800267B0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_SspiCliCallNames" ?g_SspiCliCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180016150: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumFunctionTableEntries(void * __ptr64,unsigned long,void * __ptr64,void * __ptr64,unsigned long) __ptr64" ?EnumFunctionTableEntries@NtWin32LiveSystemProvider@@UEAAJPEAXK00K@Z
0x18000B460: "public: virtual long __cdecl GenMiniDumpProviderCallbacks::EnumMemory(unsigned __int64,unsigned long) __ptr64" ?EnumMemory@GenMiniDumpProviderCallbacks@@UEAAJ_KK@Z
0x180027160: "struct _DYNAMIC_CALLS_DESC volatile g_Secur32CallsDesc" ?g_Secur32CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001F9A0: "api-ms-win-core-misc-l1-1-0.dll" ??_C@_0CA@OMOHGHMO@api?9ms?9win?9core?9misc?9l1?91?90?4dll?$AA@
0x18001BB18: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x180012620: "public: virtual void * __ptr64 __cdecl PssNtWin32LiveSystemProvider::`scalar deleting destructor'(unsigned int) __ptr64" ??_GPssNtWin32LiveSystemProvider@@UEAAPEAXI@Z
0x180025970: "struct _OLE32_CALLS volatile g_Ole32Calls" ?g_Ole32Calls@@3U_OLE32_CALLS@@C
0x18001FA50: "SspiCli.dll" ??_C@_0M@CIEJGNCK@SspiCli?4dll?$AA@
0x18001C458: "QueryProcessVmCounters failed, 0" ??_C@_0CG@EDOMNJFL@QueryProcessVmCounters?5failed?0?50@
0x180007BA0: "public: virtual long __cdecl Win32LiveSystemProvider::GetCpuInfo(unsigned short * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64,unsigned char * __ptr64,union _CPU_INFORMATION * __ptr64) __ptr64" ?GetCpuInfo@Win32LiveSystemProvider@@UEAAJPEAG00PEAEPEAT_CPU_INFORMATION@@@Z
0x18001DA28: "ThreadToken_RestrictedSids(0x%08" ??_C@_0CM@JLJBHDLM@ThreadToken_RestrictedSids?$CI0x?$CF08@
0x18001FBC8: "RoUninitialize" ??_C@_0P@LLFHBIJD@RoUninitialize?$AA@
0x18001F558: "SetCommState" ??_C@_0N@KDLJEBGM@SetCommState?$AA@
0x18001D780: "Memory read failure at %I64x:%x " ??_C@_0DF@FLPDDALO@Memory?5read?5failure?5at?5?$CFI64x?3?$CFx?5@
0x180023660: "protected: static unsigned long (__cdecl* __ptr64 Win32LiveSystemProvider::s_GetFileVersionInfoSizeExW)(unsigned long,unsigned short const * __ptr64,unsigned long * __ptr64)" ?s_GetFileVersionInfoSizeExW@Win32LiveSystemProvider@@1P6AKKPEBGPEAK@ZEA
0x18001F498: "SetConsoleTextAttribute" ??_C@_0BI@DJFAEKGH@SetConsoleTextAttribute?$AA@
0x18000B380: "public: virtual void * __ptr64 __cdecl Win32LiveAllocationProvider::Realloc(void * __ptr64,unsigned long) __ptr64" ?Realloc@Win32LiveAllocationProvider@@UEAAPEAXPEAXK@Z
0x18001A362: "__cdecl initialize_onexit_table" _initialize_onexit_table
0x18001E298: "GenWriteHandleData.TypeNameLen.W" ??_C@_0DK@HDHEMGPJ@GenWriteHandleData?4TypeNameLen?4W@
0x180009840: "public: virtual unsigned long __cdecl PssNtWin32LiveSystemProvider::GetCurrentThreadId(void) __ptr64" ?GetCurrentThreadId@PssNtWin32LiveSystemProvider@@UEAAKXZ
0x1800235F8: "__cdecl _scrt_native_startup_lock" __scrt_native_startup_lock
0x18001E060: "GenGetProcessInfo.EnumThreads(0x" ??_C@_0DD@OEFNANFG@GenGetProcessInfo?4EnumThreads?$CI0x@
0x18001C788: "Full memory stream overflowed" ??_C@_0BO@CAMGGDNE@Full?5memory?5stream?5overflowed?$AA@
0x18001FC40: "WindowsDeleteString" ??_C@_0BE@IJKKHGMH@WindowsDeleteString?$AA@
0x18001D1D0: "Software\Microsoft\Windows NT\Cu" ??_C@_1FK@MPJNMLLM@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?5?$AAN?$AAT?$AA?2?$AAC?$AAu@
0x180025FB0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreToolHelpCallsDesc" ?g_CoreToolHelpCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180026450: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreVersionCallNames" ?g_CoreVersionCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180026080: "struct _DYNAMIC_CALL_NAME volatile * volatile g_SecurityCryptoapiCallNames" ?g_SecurityCryptoapiCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001EB50: "SymFunctionTableAccess64AccessRo" ??_C@_0CH@NHODMGPE@SymFunctionTableAccess64AccessRo@
0x180001084: "public: bool __cdecl VersionQuery::GetModuleVersion(unsigned short const * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64) __ptr64" ?GetModuleVersion@VersionQuery@@QEAA_NPEBGPEAG111@Z
0x1800139B0: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetProcessTimes(void * __ptr64,struct _FILETIME * __ptr64,struct _FILETIME * __ptr64,struct _FILETIME * __ptr64) __ptr64" ?GetProcessTimes@PssNtWin32LiveSystemProvider@@UEAAJPEAXPEAU_FILETIME@@11@Z
0x180026820: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreUrlCallNames" ?g_CoreUrlCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001A440: "__cdecl _vcrt_uninitialize" __vcrt_uninitialize
0x18001DEA8: "ProcessToken_Statistics(0x%08X,%" ??_C@_0CJ@BDPGEFFD@ProcessToken_Statistics?$CI0x?$CF08X?0?$CF@
0x18001D558: "K32EnumProcessModules" ??_C@_0BG@PHNLPDLJ@K32EnumProcessModules?$AA@
0x180015640: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetThreadName(void * __ptr64,void * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?GetThreadName@NtWin32LiveSystemProvider@@UEAAJPEAX0PEAGK@Z
0x180009840: "public: virtual long __cdecl CallbackOutputProvider::SupportsStreaming(void) __ptr64" ?SupportsStreaming@CallbackOutputProvider@@UEAAJXZ
0x180020518: "__cdecl _imp_IsProcessorFeaturePresent" __imp_IsProcessorFeaturePresent
0x180026A30: "struct _DYNAMIC_CALLS_DESC volatile g_CoreDebugCallsDesc" ?g_CoreDebugCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180017CD0: "public: virtual long __cdecl NtWin32LiveSystemProvider::CloseToken(void * __ptr64) __ptr64" ?CloseToken@NtWin32LiveSystemProvider@@UEAAJPEAX@Z
0x18001CEB0: "GetThreadTimes" ??_C@_0P@NJAAGDEH@GetThreadTimes?$AA@
0x18001BCF8: "__cdecl _PLEASE_LINK_WITH_legacy_stdio_wide_specifiers.lib" __PLEASE_LINK_WITH_legacy_stdio_wide_specifiers.lib
0x18000B200: "public: virtual void __cdecl Win32FileOutputProvider::Release(void) __ptr64" ?Release@Win32FileOutputProvider@@UEAAXXZ
0x18001F978: "api-ms-win-core-debug-l1-1-1.dll" ??_C@_0CB@PADHAFAC@api?9ms?9win?9core?9debug?9l1?91?91?4dll@
0x180026120: "struct _DYNAMIC_CALL_NAME volatile * volatile g_ShlwapiIeCallNames" ?g_ShlwapiIeCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001F458: "FillConsoleOutputCharacterA" ??_C@_0BM@KOHFFKAD@FillConsoleOutputCharacterA?$AA@
0x1800088C0: "public: virtual void __cdecl Win32LiveSystemProvider::CloseThread(void * __ptr64) __ptr64" ?CloseThread@Win32LiveSystemProvider@@UEAAXPEAX@Z
0x18001E820: "Section" ??_C@_1BA@LHDKDEEN@?$AAS?$AAe?$AAc?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x180013F60: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::EnumHandleObjectInfo(unsigned __int64,unsigned short const * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?EnumHandleObjectInfo@PssNtWin32LiveSystemProvider@@UEAAJ_KPEBGKPEAKPEAXK2@Z
0x1800083D0: "public: virtual void __cdecl PssNtWin32LiveSystemProvider::FreeProcessIptTrace(void * __ptr64) __ptr64" ?FreeProcessIptTrace@PssNtWin32LiveSystemProvider@@UEAAXPEAX@Z
0x18001C0D8: "\" ??_C@_13FPGAJAPJ@?$AA?2?$AA?$AA@
0x180007D40: "public: virtual void __cdecl Win32LiveSystemProvider::GetContextSizes(unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64) __ptr64" ?GetContextSizes@Win32LiveSystemProvider@@UEAAXPEAK00@Z
0x18001D5A0: "EnumProcessModules" ??_C@_0BD@FIEJBLME@EnumProcessModules?$AA@
0x18001C300: "WriteFunctionTable.RawEntries.Wr" ??_C@_0DJ@ONJKACBM@WriteFunctionTable?4RawEntries?4Wr@
0x1800078E0: "public: virtual void __cdecl Win32LiveSystemProvider::Release(void) __ptr64" ?Release@Win32LiveSystemProvider@@UEAAXXZ
0x18001FA90: "SwitchDesktop" ??_C@_0O@LCGKNMD@SwitchDesktop?$AA@
0x18001BA08: "__cdecl _imp_HeapAlloc" __imp_HeapAlloc
0x18001C0E0: "api-ms-win-core-version-l1-1-0.d" ??_C@_1EG@NOIDINJJ@?$AAa?$AAp?$AAi?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAc?$AAo?$AAr?$AAe?$AA?9?$AAv?$AAe?$AAr?$AAs?$AAi?$AAo?$AAn?$AA?9?$AAl?$AA1?$AA?9?$AA1?$AA?9?$AA0?$AA?4?$AAd@
0x18001ED38: "NtDebugContinue" ??_C@_0BA@CPDFMFD@NtDebugContinue?$AA@
0x18001BA60: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x18001D910: "ThreadToken(%d,%I64x,%d,%d)" ??_C@_0BM@NBCBIPKH@ThreadToken?$CI?$CFd?0?$CFI64x?0?$CFd?0?$CFd?$CJ?$AA@
0x18001FEC8: "CertFindCertificateInStore" ??_C@_0BL@FFHIDOLI@CertFindCertificateInStore?$AA@
0x18001F6E0: "ext-ms-win-kernel32-package-l1-1" ??_C@_0CH@MJKNJFE@ext?9ms?9win?9kernel32?9package?9l1?91@
0x18001BB68: "__cdecl _imp_AcquireSRWLockExclusive" __imp_AcquireSRWLockExclusive
0x18000AC30: "protected: static unsigned long __cdecl Win32LiveSystemProvider::GetFileVersionInfoSizeAStub(char const * __ptr64,unsigned long * __ptr64)" ?GetFileVersionInfoSizeAStub@Win32LiveSystemProvider@@KAKPEBDPEAK@Z
0x18001E7F0: "Thread" ??_C@_1O@CDOGJPJJ@?$AAT?$AAh?$AAr?$AAe?$AAa?$AAd?$AA?$AA@
0x18001C178: "VerQueryValueW" ??_C@_0P@BMNOKKJF@VerQueryValueW?$AA@
0x180020300: "api-ms-win-service-core-l1-1-1.d" ??_C@_0CD@NKEFLBDO@api?9ms?9win?9service?9core?9l1?91?91?4d@
0x180007D60: "public: virtual void __cdecl Win32LiveSystemProvider::GetContextSizesEx(unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long) __ptr64" ?GetContextSizesEx@Win32LiveSystemProvider@@UEAAXPEAK00K@Z
0x18001B850: "const NtWin32LiveSystemProvider::`vftable'{for `MiniDumpVmHookedProvider'}" ??_7NtWin32LiveSystemProvider@@6BMiniDumpVmHookedProvider@@@
0x1800028A8: "long __cdecl CalculateSizeForModules(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?CalculateSizeForModules@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x18000AC90: "protected: static int __cdecl Win32LiveSystemProvider::GetFileVersionInfoAStub(char const * __ptr64,unsigned long,unsigned long,void * __ptr64)" ?GetFileVersionInfoAStub@Win32LiveSystemProvider@@KAHPEBDKKPEAX@Z
0x18000BA40: "int __cdecl GenExecuteReadMemoryFailureCallback(struct _MINIDUMP_STATE * __ptr64,unsigned __int64,unsigned long,long)" ?GenExecuteReadMemoryFailureCallback@@YAHPEAU_MINIDUMP_STATE@@_KKJ@Z
0x1800264C0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreTimeZoneCallsDesc" ?g_CoreTimeZoneCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001A3B8: "__cdecl o_malloc" _o_malloc
0x18001D460: "Software\Microsoft\Windows NT\Cu" ??_C@_0EH@CNCIMMPN@Software?2Microsoft?2Windows?5NT?2Cu@
0x180019BCC: "__cdecl _scrt_dllmain_before_initialize_c" __scrt_dllmain_before_initialize_c
0x18001E478: "GenWriteHandleOperations stream " ??_C@_0CN@JNAKAOA@GenWriteHandleOperations?5stream?5@
0x18001F6C0: "OpenPackageInfoByFullName" ??_C@_0BK@JLILJBME@OpenPackageInfoByFullName?$AA@
0x18001D5F8: "GetFileVersionInfoSizeExA" ??_C@_0BK@MODCDHIO@GetFileVersionInfoSizeExA?$AA@
0x1800196B0: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x180018F20: "public: virtual long __cdecl StackProviderDataTarget::EnumMemoryRegion(unsigned __int64,unsigned int) __ptr64" ?EnumMemoryRegion@StackProviderDataTarget@@UEAAJ_KI@Z
0x18001BC60: "__cdecl _imp__initterm" __imp__initterm
0x18001A388: "__cdecl o__strlwr_s" _o__strlwr_s
0x180021AF4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-debug-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-debug-l1-1-0
0x18001E558: "__cdecl GUID_a5664f95_0af4_4a1b_960e_2f3346b4214c" _GUID_a5664f95_0af4_4a1b_960e_2f3346b4214c
0x180020068: "CreateServiceW" ??_C@_0P@FCLKEOKA@CreateServiceW?$AA@
0x180026320: "struct _DYNAMIC_CALLS_DESC volatile g_Kernel32CallsDesc" ?g_Kernel32CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180025C40: "struct KERNEL32_CALLS_MDWD volatile g_Kernel32CallsMdwd" ?g_Kernel32CallsMdwd@@3UKERNEL32_CALLS_MDWD@@C
0x180025340: "struct _DOWNLEVEL_KERNEL32_L1_CALLS volatile g_DownlevelKernel32L1Calls" ?g_DownlevelKernel32L1Calls@@3U_DOWNLEVEL_KERNEL32_L1_CALLS@@C
0x1800090D0: "public: virtual long __cdecl Win32LiveSystemProvider::GetValidVirtualRange(void * __ptr64,unsigned __int64,unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetValidVirtualRange@Win32LiveSystemProvider@@UEAAJPEAX_KKPEA_KPEAK@Z
0x180027770: "struct _DYNAMIC_CALLS_DESC volatile g_ExtKernel32PackageL1CallsDesc" ?g_ExtKernel32PackageL1CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001B988: "__cdecl _imp_SetLastError" __imp_SetLastError
0x18001E5C8: "GenAddMemoryBlock total size ove" ??_C@_0CG@EEOJIBND@GenAddMemoryBlock?5total?5size?5ove@
0x18001B298: "const NullStatusProvider::`vftable'" ??_7NullStatusProvider@@6B@
0x18001F0A0: "DebugSetProcessKillOnExit" ??_C@_0BK@MKDCGKPG@DebugSetProcessKillOnExit?$AA@
0x180008840: "public: virtual long __cdecl Win32LiveSystemProvider::OpenThread(unsigned long,int,unsigned long,void * __ptr64 * __ptr64) __ptr64" ?OpenThread@Win32LiveSystemProvider@@UEAAJKHKPEAPEAX@Z
0x180018750: RtlMrdataReleaseSectionWriteAccess
0x180025018: "struct _CORE_JOB_L2_CALLS volatile g_CoreJobL2Calls" ?g_CoreJobL2Calls@@3U_CORE_JOB_L2_CALLS@@C
0x18001D728: "Module(0x%I64x) will not be incl" ??_C@_0CF@OMOJCABO@Module?$CI0x?$CFI64x?$CJ?5will?5not?5be?5incl@
0x18001BA58: "__cdecl _imp_GetModuleFileNameW" __imp_GetModuleFileNameW
0x18001BB80: "__cdecl _imp_GetVersionExA" __imp_GetVersionExA
0x18001F4B0: "GetTempPathW" ??_C@_0N@DAENKDLF@GetTempPathW?$AA@
0x180027080: "struct _DYNAMIC_CALLS_DESC volatile g_DownlevelKernel32L2CallsDesc" ?g_DownlevelKernel32L2CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001DF78: "GenGetAuxMemory(%ws) failed, 0x%" ??_C@_0CE@CALGHML@GenGetAuxMemory?$CI?$CFws?$CJ?5failed?0?50x?$CF@
0x18001D100: "api-ms-win-core-toolhelp-l1-1-0." ??_C@_0CE@OAKIJJDD@api?9ms?9win?9core?9toolhelp?9l1?91?90?4@
0x18001F150: "DuplicateHandle" ??_C@_0BA@KKBHKMMH@DuplicateHandle?$AA@
0x18001BB88: "__cdecl _imp_GetVersionExW" __imp_GetVersionExW
0x18001EF18: "RtlWow64GetThreadSelectorEntry" ??_C@_0BP@FNMIBGNJ@RtlWow64GetThreadSelectorEntry?$AA@
0x18001F318: "DeleteFiber" ??_C@_0M@DFGOICCC@DeleteFiber?$AA@
0x180009660: "public: virtual long __cdecl Win32LiveSystemProvider::GetFunctionTableAccessProc(void * __ptr64 (__cdecl*)(void * __ptr64,unsigned __int64)) __ptr64" ?GetFunctionTableAccessProc@Win32LiveSystemProvider@@UEAAJP6APEAXPEAX_K@Z@Z
0x18001FD50: "PathFindFileNameA" ??_C@_0BC@KNIGDLDO@PathFindFileNameA?$AA@
0x180018A80: "public: static void * __ptr64 __cdecl StackProviderDataTarget::StackProviderFunctionTableAccess64(void * __ptr64,unsigned __int64,unsigned __int64)" ?StackProviderFunctionTableAccess64@StackProviderDataTarget@@SAPEAXPEAX_K1@Z
0x18001CA20: "MarshalExceptionPointers.ExRecor" ??_C@_0EF@IJOOAGOL@MarshalExceptionPointers?4ExRecor@
0x18001B020: "const Win32LiveAllocationProvider::`vftable'" ??_7Win32LiveAllocationProvider@@6B@
0x18000F500: "public: virtual long __cdecl GenClrDataTarget::GetThreadContext(unsigned int,unsigned int,unsigned int,unsigned char * __ptr64) __ptr64" ?GetThreadContext@GenClrDataTarget@@UEAAJIIIPEAE@Z
0x1800189F0: "void * __ptr64 __cdecl FunctionTableAccessProc64(void * __ptr64,unsigned __int64)" ?FunctionTableAccessProc64@@YAPEAXPEAX_K@Z
0x18001A33E: "__cdecl o__configure_narrow_argv" _o__configure_narrow_argv
0x18001F060: "DebugActiveProcessStop" ??_C@_0BH@GIBMBPOA@DebugActiveProcessStop?$AA@
0x18001EE40: "RtlDestroyProcessParameters" ??_C@_0BM@GIFABGKB@RtlDestroyProcessParameters?$AA@
0x180019B2C: "__cdecl _scrt_initialize_default_local_stdio_options" __scrt_initialize_default_local_stdio_options
0x180020138: "GetOldestEventLogRecord" ??_C@_0BI@DELAMBGK@GetOldestEventLogRecord?$AA@
0x18001E628: "RtlCreateQueryDebugBuffer" ??_C@_0BK@DLDGDFJN@RtlCreateQueryDebugBuffer?$AA@
0x18001CB58: "x86" ??_C@_17NIABIIAO@?$AAx?$AA8?$AA6?$AA?$AA@
0x18001F8A8: "api-ms-win-core-console-l2-1-0.d" ??_C@_0CD@HENCEBKH@api?9ms?9win?9core?9console?9l2?91?90?4d@
0x180017500: "public: virtual long __cdecl NtWin32LiveSystemProvider::QueryMiscInformation(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?QueryMiscInformation@NtWin32LiveSystemProvider@@UEAAJPEAXKPEAK0K1@Z
0x18001BC90: "__cdecl _imp_NtCreateFile" __imp_NtCreateFile
0x18001D328: "WinVerifyTrust" ??_C@_0P@CBOPOJKE@WinVerifyTrust?$AA@
0x180019D40: "__cdecl _scrt_initialize_onexit_tables" __scrt_initialize_onexit_tables
0x18001EBE0: "RtlWow64GetThreadContext" ??_C@_0BJ@IMKGDDOM@RtlWow64GetThreadContext?$AA@
0x18001D410: "Software\Microsoft\Windows NT\Cu" ??_C@_0ED@KBJEKKKI@Software?2Microsoft?2Windows?5NT?2Cu@
0x18001BB10: "__cdecl _imp_SuspendThread" __imp_SuspendThread
0x18001BCD0: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x18001CDB0: "OpenThread" ??_C@_0L@EHKLHJ@OpenThread?$AA@
0x18001D7B8: "GenGetImageSections.Read(0x%I64x" ??_C@_0DH@IFPOPLPH@GenGetImageSections?4Read?$CI0x?$CFI64x@
0x18001CA70: "MarshalExceptionPointers.CxRecor" ??_C@_0EF@HFBOJHKH@MarshalExceptionPointers?4CxRecor@
0x18000AD04: "protected: bool __cdecl Win32LiveSystemProvider::AddHandleOp(struct _AVRF_HANDLE_OPERATION * __ptr64) __ptr64" ?AddHandleOp@Win32LiveSystemProvider@@IEAA_NPEAU_AVRF_HANDLE_OPERATION@@@Z
0x180003898: "long __cdecl CalculateStreamInfo(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,int,struct _MINIDUMP_USER_STREAM * __ptr64,unsigned long,struct _LIST_ENTRY * __ptr64)" ?CalculateStreamInfo@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_MINIDUMP_STREAM_INFO@@HPEAU_MINIDUMP_USER_STREAM@@KPEAU_LIST_ENTRY@@@Z
0x18000454C: "int __cdecl FilterVmRegion(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_MEMORY_INFO * __ptr64)" ?FilterVmRegion@@YAHPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_MEMORY_INFO@@@Z
0x180025130: "struct _CORE_COMM_CALLS volatile g_CoreCommCalls" ?g_CoreCommCalls@@3U_CORE_COMM_CALLS@@C
0x18001F398: "GetPrivateProfileIntW" ??_C@_0BG@OGNPECDI@GetPrivateProfileIntW?$AA@
0x180016C80: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumPebMemory(void * __ptr64,unsigned long,unsigned __int64,unsigned long,class MiniDumpProviderCallbacks * __ptr64) __ptr64" ?EnumPebMemory@NtWin32LiveSystemProvider@@UEAAJPEAXK_KKPEAVMiniDumpProviderCallbacks@@@Z
0x18001F7C8: "CoTaskMemFree" ??_C@_0O@MIBPKJDN@CoTaskMemFree?$AA@
0x180019F30: "__cdecl _crt_debugger_hook" __crt_debugger_hook
0x18001F790: "CoCreateInstance" ??_C@_0BB@FBCNKNOO@CoCreateInstance?$AA@
0x18001FC58: "SysAllocString" ??_C@_0P@DMOFHADO@SysAllocString?$AA@
0x18001BB08: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x180008F00: "public: virtual long __cdecl Win32LiveSystemProvider::ReadAllVirtual(void * __ptr64,unsigned __int64,void * __ptr64,unsigned long) __ptr64" ?ReadAllVirtual@Win32LiveSystemProvider@@UEAAJPEAX_K0K@Z
0x18001EF58: "RtlGetExtendedContextLength" ??_C@_0BM@BLANBBMM@RtlGetExtendedContextLength?$AA@
0x180020150: "OpenEventLogA" ??_C@_0O@EDGJEOGK@OpenEventLogA?$AA@
0x180009820: "public: virtual void __cdecl Win32LiveSystemProvider::FinishHandleOperationsEnum(unsigned __int64) __ptr64" ?FinishHandleOperationsEnum@Win32LiveSystemProvider@@UEAAX_K@Z
0x18001EC00: "api-ms-win-core-wow64-l1-1-2.dll" ??_C@_0CB@DIKGKHCI@api?9ms?9win?9core?9wow64?9l1?91?92?4dll@
0x18000FA68: "long __cdecl GenGetHandleData(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?GenGetHandleData@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@@Z
0x18001EC58: "DbgPrint" ??_C@_08IGPPDFPO@DbgPrint?$AA@
0x1800251A8: "struct _SECURITY_CRYPTOAPI_CALLS volatile g_SecurityCryptoapiCalls" ?g_SecurityCryptoapiCalls@@3U_SECURITY_CRYPTOAPI_CALLS@@C
0x180025488: "struct _SECURITY_LSALOOKUP_CALLS volatile g_SecurityLsaLookupCalls" ?g_SecurityLsaLookupCalls@@3U_SECURITY_LSALOOKUP_CALLS@@C
0x18001DBC0: "Unable to add debug directory %x" ??_C@_0EC@PBDAEONI@Unable?5to?5add?5debug?5directory?5?$CFx@
0x180020268: "CryptGenRandom" ??_C@_0P@HGPEDCEI@CryptGenRandom?$AA@
0x18000EBCC: "void __cdecl GenFreeProcessObject(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _LIST_ENTRY * __ptr64)" ?GenFreeProcessObject@@YAXPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_LIST_ENTRY@@@Z
0x18001D0D8: "api-ms-win-core-xstate-l2-1-0.dl" ??_C@_0CC@MCIAFGEM@api?9ms?9win?9core?9xstate?9l2?91?90?4dl@
0x180015A40: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetPeb(void * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetPeb@NtWin32LiveSystemProvider@@UEAAJPEAXPEA_KPEAK@Z
0x180025C28: "struct COREWOW64_CALLS_MDWD volatile g_CoreWow64CallsMdwd" ?g_CoreWow64CallsMdwd@@3UCOREWOW64_CALLS_MDWD@@C
0x1800153F0: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetTeb(void * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetTeb@NtWin32LiveSystemProvider@@UEAAJPEAXPEA_KPEAK@Z
0x180001250: "struct _MINIDUMP_HANDLE_DESCRIPTOR_2 * __ptr64 __cdecl AddressIsHandle(struct _INTERNAL_PROCESS * __ptr64,unsigned __int64)" ?AddressIsHandle@@YAPEAU_MINIDUMP_HANDLE_DESCRIPTOR_2@@PEAU_INTERNAL_PROCESS@@_K@Z
0x18001BC98: "__cdecl _imp_RtlNtStatusToDosError" __imp_RtlNtStatusToDosError
0x18001EF78: "RtlInitializeExtendedContext" ??_C@_0BN@BINLFFKD@RtlInitializeExtendedContext?$AA@
0x18000BB20: "unsigned char __cdecl AddressReferenced(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_THREAD * __ptr64,unsigned __int64,unsigned char,unsigned char)" ?AddressReferenced@@YAEPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_THREAD@@_KEE@Z
0x1800051BC: "void __cdecl WriteKernelMinidump(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteKernelMinidump@@YAXPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@@Z
0x18001A326: "__cdecl o___stdio_common_vswprintf_s" _o___stdio_common_vswprintf_s
0x180016330: "public: virtual void __cdecl NtWin32LiveSystemProvider::FinishProcessEnum(void) __ptr64" ?FinishProcessEnum@NtWin32LiveSystemProvider@@UEAAXXZ
0x18001E390: "GenWriteHandleData.InfoHdr.Write" ??_C@_0DJ@GPFMAKIB@GenWriteHandleData?4InfoHdr?4Write@
0x18001C3B8: "WriteTokenInformation.ThreadToke" ??_C@_0DI@GCLLLGEO@WriteTokenInformation?4ThreadToke@
0x180026490: "struct _DYNAMIC_CALLS_DESC volatile g_EventlogLegacyCallsDesc" ?g_EventlogLegacyCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180014B20: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::OpenToken(unsigned long,unsigned long,void * __ptr64,void * __ptr64 * __ptr64) __ptr64" ?OpenToken@PssNtWin32LiveSystemProvider@@UEAAJKKPEAXPEAPEAX@Z
0x18001B968: "__cdecl _imp_IsDebuggerPresent" __imp_IsDebuggerPresent
0x18001F588: "WaitCommEvent" ??_C@_0O@DPNKCKJG@WaitCommEvent?$AA@
0x18001E780: "PssWalkMarkerRewind" ??_C@_0BE@HIAJPIEK@PssWalkMarkerRewind?$AA@
0x18001E178: "GenGetProcessInfo.EnumFunctionTa" ??_C@_0DC@BNCHDJBE@GenGetProcessInfo?4EnumFunctionTa@
0x180007A00: "public: virtual long __cdecl Win32LiveSystemProvider::OpenToken(unsigned long,unsigned long,void * __ptr64,void * __ptr64 * __ptr64) __ptr64" ?OpenToken@Win32LiveSystemProvider@@UEAAJKKPEAXPEAPEAX@Z
0x18001BBA0: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x18001BCF0: "__cdecl _xi_a" __xi_a
0x1800268E0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreConsoleCallsDesc" ?g_CoreConsoleCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18000A690: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetThreadName(void * __ptr64,void * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?GetThreadName@PssNtWin32LiveSystemProvider@@UEAAJPEAX0PEAGK@Z
0x1800270B0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreProcessThreadsCallNames" ?g_CoreProcessThreadsCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001DF08: "GenIncludeUnwindInfoMemory.Enum(" ??_C@_0DO@KKPKHHMO@GenIncludeUnwindInfoMemory?4Enum?$CI@
0x18001F418: "GetConsoleScreenBufferInfo" ??_C@_0BL@NAIJNMLL@GetConsoleScreenBufferInfo?$AA@
0x18001B970: api-ms-win-core-debug-l1-1-0_NULL_THUNK_DATA
0x180019C18: "__cdecl _scrt_dllmain_crt_thread_detach" __scrt_dllmain_crt_thread_detach
0x18001ECF8: "NtCreateDebugObject" ??_C@_0BE@HLOEAMPP@NtCreateDebugObject?$AA@
0x1800200D8: "CloseEventLog" ??_C@_0O@CMPADMMI@CloseEventLog?$AA@
0x18001EAE0: "dbghelp.dll" ??_C@_1BI@HFOADCMA@?$AAd?$AAb?$AAg?$AAh?$AAe?$AAl?$AAp?$AA?4?$AAd?$AAl?$AAl?$AA?$AA@
0x18001CB60: "IA64" ??_C@_19DGIHPCNG@?$AAI?$AAA?$AA6?$AA4?$AA?$AA@
0x180019B50: "__cdecl _scrt_acquire_startup_lock" __scrt_acquire_startup_lock
0x1800042DC: "long __cdecl WriteUserStreams(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,unsigned long * __ptr64,struct _MINIDUMP_USER_STREAM * __ptr64,unsigned long)" ?WriteUserStreams@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAKPEAU_MINIDUMP_USER_STREAM@@K@Z
0x18001D170: "api-ms-win-downlevel-kernel32-l2" ??_C@_0CJ@CONBDPME@api?9ms?9win?9downlevel?9kernel32?9l2@
0x18000B68C: "int __cdecl GenAddUpdateMemoryRegion(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,int,unsigned __int64,unsigned char * __ptr64,unsigned long)" ?GenAddUpdateMemoryRegion@@YAHPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@H_KPEAEK@Z
0x18001CE00: "Module32FirstW" ??_C@_0P@FPNNECFF@Module32FirstW?$AA@
0x18001FC28: "WindowsCreateString" ??_C@_0BE@POPPOKBD@WindowsCreateString?$AA@
0x18001E648: "RtlDestroyQueryDebugBuffer" ??_C@_0BL@KPBKBMEI@RtlDestroyQueryDebugBuffer?$AA@
0x18001C5E0: "Full memory minidump produced me" ??_C@_0CM@JNPJEBFI@Full?5memory?5minidump?5produced?5me@
0x18001D4D0: "CallNtPowerInformation" ??_C@_0BH@GPGFINAB@CallNtPowerInformation?$AA@
0x18001D588: "K32GetProcessMemoryInfo" ??_C@_0BI@OHEFACEI@K32GetProcessMemoryInfo?$AA@
0x1800182D8: "void __cdecl GenImageNtHdr32To64(struct _IMAGE_NT_HEADERS * __ptr64,struct _IMAGE_NT_HEADERS64 * __ptr64)" ?GenImageNtHdr32To64@@YAXPEAU_IMAGE_NT_HEADERS@@PEAU_IMAGE_NT_HEADERS64@@@Z
0x180002268: "long __cdecl WriteUnloadedModuleList(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteUnloadedModuleList@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x18001EA28: "GetSidSubAuthority" ??_C@_0BD@LMGFHOAE@GetSidSubAuthority?$AA@
0x18001D358: "WTHelperGetProvSignerFromChain" ??_C@_0BP@BBMCBEAG@WTHelperGetProvSignerFromChain?$AA@
0x18000C22C: "long __cdecl GenFilterARMContext(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_THREAD * __ptr64,void * __ptr64,unsigned long,unsigned char)" ?GenFilterARMContext@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_THREAD@@PEAXKE@Z
0x18001D688: "GetFileVersionInfoW" ??_C@_0BE@IEOIIDEN@GetFileVersionInfoW?$AA@
0x18000A9B8: "protected: long __cdecl Win32LiveSystemProvider::LoadVersion(void) __ptr64" ?LoadVersion@Win32LiveSystemProvider@@IEAAJXZ
0x18001A332: "__cdecl o__cexit" _o__cexit
0x18001A3A0: "__cdecl wsplitpath_s" _wsplitpath_s
0x18001D8D8: "GenAllocateThreadObject.GetTebIn" ??_C@_0DI@KHCHFPEM@GenAllocateThreadObject?4GetTebIn@
0x180008830: "public: virtual long __cdecl Win32LiveSystemProvider::WriteKernelMinidump(void * __ptr64,void * __ptr64,unsigned long,void * __ptr64 * __ptr64,unsigned long,unsigned long) __ptr64" ?WriteKernelMinidump@Win32LiveSystemProvider@@UEAAJPEAX0KPEAPEAXKK@Z
0x180018618: RtlpMrdataObtainSection
0x18001D9D8: "ThreadToken_Privileges(0x%08X,%d" ??_C@_0CI@KKAKCLKL@ThreadToken_Privileges?$CI0x?$CF08X?0?$CFd@
0x18001BCB8: "__cdecl _imp_RtlRunOnceExecuteOnce" __imp_RtlRunOnceExecuteOnce
0x1800278C0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_NtDllCallNames" ?g_NtDllCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180009660: "public: virtual long __cdecl Win32LiveSystemProvider::EnumFunctionTableEntries(void * __ptr64,unsigned long,void * __ptr64,void * __ptr64,unsigned long) __ptr64" ?EnumFunctionTableEntries@Win32LiveSystemProvider@@UEAAJPEAXK00K@Z
0x18001E798: "PssWalkMarkerSeekToBeginning" ??_C@_0BN@PDJAHOAE@PssWalkMarkerSeekToBeginning?$AA@
0x18001FAE8: "CoInitializeSecurity" ??_C@_0BF@GDAFCOOE@CoInitializeSecurity?$AA@
0x18001D3B0: "\StringFileInfo\040904b0\Origina" ??_C@_1FE@CFCMNGIF@?$AA?2?$AAS?$AAt?$AAr?$AAi?$AAn?$AAg?$AAF?$AAi?$AAl?$AAe?$AAI?$AAn?$AAf?$AAo?$AA?2?$AA0?$AA4?$AA0?$AA9?$AA0?$AA4?$AAb?$AA0?$AA?2?$AAO?$AAr?$AAi?$AAg?$AAi?$AAn?$AAa@
0x18001A37C: "__cdecl seh_filter_dll" _seh_filter_dll
0x18000DB0C: "long __cdecl GenAllocateModuleObject(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned short * __ptr64,unsigned __int64,unsigned long,struct _INTERNAL_MODULE * __ptr64 * __ptr64)" ?GenAllocateModuleObject@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAG_KKPEAPEAU_INTERNAL_MODULE@@@Z
0x18001BBB8: "__cdecl _imp__execute_onexit_table" __imp__execute_onexit_table
0x180015E30: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumFunctionTables(unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64,void * __ptr64,unsigned long,void * __ptr64 * __ptr64,class MiniDumpProviderCallbacks * __ptr64) __ptr64" ?EnumFunctionTables@NtWin32LiveSystemProvider@@UEAAJPEA_K00PEAKPEAXKPEAPEAXPEAVMiniDumpProviderCallbacks@@@Z
0x180021A90: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0
0x18001B9F0: "__cdecl _imp_HeapCreate" __imp_HeapCreate
0x18001D038: "api-ms-win-security-base-l1-1-0." ??_C@_0CE@IBLDLJJO@api?9ms?9win?9security?9base?9l1?91?90?4@
0x18001BAD8: api-ms-win-core-memory-l1-1-0_NULL_THUNK_DATA
0x18001CCB0: "AVX XState info is not allowed i" ??_C@_0HJ@CEBDILEG@AVX?5XState?5info?5is?5not?5allowed?5i@
0x1800113AC: "struct _VA_RANGE_REF * __ptr64 __cdecl GenCreateFilterRangeNode(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned long,enum MEMBLOCK_TYPE,enum MEMBLOCK_FILTER_TYPE)" ?GenCreateFilterRangeNode@@YAPEAU_VA_RANGE_REF@@PEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@_KKW4MEMBLOCK_TYPE@@W4MEMBLOCK_FILTER_TYPE@@@Z
0x18000B4A0: "public: virtual void __cdecl GenMiniDumpProviderCallbacks::FreeMemory(void * __ptr64) __ptr64" ?FreeMemory@GenMiniDumpProviderCallbacks@@UEAAXPEAX@Z
0x180019878: "__cdecl _report_rangecheckfailure" __report_rangecheckfailure
0x18001C0C0: "__cdecl pRawDllMain" _pRawDllMain
0x1800096B0: "public: virtual long __cdecl Win32LiveSystemProvider::StartHandleOperationsEnum(void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64,struct _AVRF_HANDLE_OPERATION * __ptr64 * __ptr64) __ptr64" ?StartHandleOperationsEnum@Win32LiveSystemProvider@@UEAAJPEAXKPEA_KPEAKPEAPEAU_AVRF_HANDLE_OPERATION@@@Z
0x18001F2F0: "CreateFiber" ??_C@_0M@GHMCMACD@CreateFiber?$AA@
0x180016C30: "public: virtual void __cdecl NtWin32LiveSystemProvider::FinishHandleEnum(void) __ptr64" ?FinishHandleEnum@NtWin32LiveSystemProvider@@UEAAXXZ
0x180023668: "protected: static int (__cdecl* __ptr64 Win32LiveSystemProvider::s_GetFileVersionInfoExA)(unsigned long,char const * __ptr64,unsigned long,unsigned long,void * __ptr64)" ?s_GetFileVersionInfoExA@Win32LiveSystemProvider@@1P6AHKPEBDKKPEAX@ZEA
0x18001D9A8: "ThreadToken_PrimaryGroup(0x%08X," ??_C@_0CK@OELBBJBC@ThreadToken_PrimaryGroup?$CI0x?$CF08X?0@
0x1800179D0: "public: virtual long __cdecl NtWin32LiveSystemProvider::QueryTokenInformation(void * __ptr64,unsigned long,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?QueryTokenInformation@NtWin32LiveSystemProvider@@UEAAJPEAXK0KPEAK@Z
0x18001A11C: "__cdecl _isa_available_init" __isa_available_init
0x180009840: "public: virtual unsigned long __cdecl StackProviderDataTarget::Release(void) __ptr64" ?Release@StackProviderDataTarget@@UEAAKXZ
0x180019728: "void __cdecl operator delete(void * __ptr64)" ??3@YAXPEAX@Z
0x18001DB08: "GenReadTlsDirectory(0x%I64x, %ws" ??_C@_0DA@HKEDKJHG@GenReadTlsDirectory?$CI0x?$CFI64x?0?5?$CFws@
0x18001EC68: "DbgPrompt" ??_C@_09ILCMGOEO@DbgPrompt?$AA@
0x180012FE0: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::EnumThreads(unsigned long * __ptr64) __ptr64" ?EnumThreads@PssNtWin32LiveSystemProvider@@UEAAJPEAK@Z
0x18001F2A8: "CreateWaitableTimerExW" ??_C@_0BH@JPFFNBDL@CreateWaitableTimerExW?$AA@
0x180025EC0: "struct _DYNAMIC_CALLS_DESC volatile g_ServiceCoreCallsDesc" ?g_ServiceCoreCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180007A40: "__cdecl get_startup_argv_mode" _get_startup_argv_mode
0x18001CE58: "GetLongPathNameW" ??_C@_0BB@PPFKPLJJ@GetLongPathNameW?$AA@
0x18001D5D0: "GetProcessMemoryInfo" ??_C@_0BF@NDAFMACL@GetProcessMemoryInfo?$AA@
0x180014DB0: "[thunk]:public: virtual void * __ptr64 __cdecl PssNtWin32LiveSystemProvider::`vector deleting destructor'`adjustor{8}' (unsigned int) __ptr64" ??_EPssNtWin32LiveSystemProvider@@W7EAAPEAXI@Z
0x180005B34: MiniDumpProvideDump
0x180021A54: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0
0x18001C7D8: "WriteFullMemory.QueryVirtual(0x%" ??_C@_0DO@ICNLLNGI@WriteFullMemory?4QueryVirtual?$CI0x?$CF@
0x1800207E8: "__cdecl _rtc_izz" __rtc_izz
0x18001E350: "GenWriteHandleData.ObjectName.Wr" ??_C@_0DJ@JHIGMCPB@GenWriteHandleData?4ObjectName?4Wr@
0x180019700: "__cdecl _security_check_cookie" __security_check_cookie
0x18000A2D0: "public: virtual long __cdecl Win32LiveSystemProvider::GetClrEnum(unsigned short * __ptr64,struct ICLRDataTarget * __ptr64,struct ICLRDataEnumMemoryRegions * __ptr64 * __ptr64) __ptr64" ?GetClrEnum@Win32LiveSystemProvider@@UEAAJPEAGPEAUICLRDataTarget@@PEAPEAUICLRDataEnumMemoryRegions@@@Z
0x18001BCE8: "__cdecl _xc_z" __xc_z
0x18001F180: "IsWow64Process" ??_C@_0P@LKABJJMO@IsWow64Process?$AA@
0x18001F380: "GetComputerNameExW" ??_C@_0BD@EKKKIMMJ@GetComputerNameExW?$AA@
0x18000B4BC: "void * __ptr64 __cdecl AllocMemory(struct _MINIDUMP_STATE * __ptr64,unsigned long)" ?AllocMemory@@YAPEAXPEAU_MINIDUMP_STATE@@K@Z
0x18001BB38: api-ms-win-core-processthreads-l1-1-0_NULL_THUNK_DATA
0x18001FE48: "api-ms-win-downlevel-shlwapi-l1-" ??_C@_0CI@BHCIHONH@api?9ms?9win?9downlevel?9shlwapi?9l1?9@
0x18001E6D0: "PssWalkSnapshot" ??_C@_0BA@OJAEAAF@PssWalkSnapshot?$AA@
0x180011460: "long __cdecl GenAddExtendFilterList(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _VA_RANGE_REF * __ptr64 * __ptr64,unsigned __int64,unsigned long,enum MEMBLOCK_TYPE,enum MEMBLOCK_FILTER_TYPE)" ?GenAddExtendFilterList@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAPEAU_VA_RANGE_REF@@_KKW4MEMBLOCK_TYPE@@W4MEMBLOCK_FILTER_TYPE@@@Z
0x18001BA30: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x1800263B0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreHandleCallsDesc" ?g_CoreHandleCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180026150: "struct _DYNAMIC_CALLS_DESC volatile g_SecurityLsaLookupCallsDesc" ?g_SecurityLsaLookupCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001C1E0: "WriteMemoryFromProcess.Read(0x%I" ??_C@_0DK@LKDCMBOK@WriteMemoryFromProcess?4Read?$CI0x?$CFI@
0x18001CBC0: "Invalid pointer size (0x%x)" ??_C@_0BM@LOADNPIP@Invalid?5pointer?5size?5?$CI0x?$CFx?$CJ?$AA@
0x18001BB00: "__cdecl _imp_GetPriorityClass" __imp_GetPriorityClass
0x18001DD38: "GenAllocateProcessObject.GetPeb(" ??_C@_0DF@HAINKCLA@GenAllocateProcessObject?4GetPeb?$CI@
0x180025950: "struct _USER32_CALLS volatile g_User32Calls" ?g_User32Calls@@3U_USER32_CALLS@@C
0x18000B330: "public: virtual void __cdecl Win32LiveAllocationProvider::Release(void) __ptr64" ?Release@Win32LiveAllocationProvider@@UEAAXXZ
0x180012540: "public: __cdecl PssNtWin32LiveSystemProvider::PssNtWin32LiveSystemProvider(class MiniDumpAllocationProvider * __ptr64,class MiniDumpStatusProvider * __ptr64,struct HPSS__ * __ptr64,unsigned long) __ptr64" ??0PssNtWin32LiveSystemProvider@@QEAA@PEAVMiniDumpAllocationProvider@@PEAVMiniDumpStatusProvider@@PEAUHPSS__@@K@Z
0x18001EAA8: "OutOfProcessFunctionTableCallbac" ??_C@_0CC@HDLCAPFJ@OutOfProcessFunctionTableCallbac@
0x180025FE0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_MprCallNames" ?g_MprCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001A440: "__cdecl _vcrt_uninitialize_critical" __vcrt_uninitialize_critical
0x1800276D0: "struct _DYNAMIC_CALLS_DESC volatile g_ApiMsWinCoreComL1CallsDesc" ?g_ApiMsWinCoreComL1CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180003E00: "long __cdecl WriteDirectoryTable(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _MINIDUMP_USER_STREAM * __ptr64,unsigned long,struct _LIST_ENTRY * __ptr64)" ?WriteDirectoryTable@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@PEAU_MINIDUMP_USER_STREAM@@KPEAU_LIST_ENTRY@@@Z
0x18001C5B8: "%ws.%ws,%u.%u.%u.%u" ??_C@_1CI@NPMIABJN@?$AA?$CF?$AAw?$AAs?$AA?4?$AA?$CF?$AAw?$AAs?$AA?0?$AA?$CF?$AAu?$AA?4?$AA?$CF?$AAu?$AA?4?$AA?$CF?$AAu?$AA?4?$AA?$CF?$AAu?$AA?$AA@
0x18001B3D0: "const GenClrDataEnumMemoryRegionsCallback::`vftable'" ??_7GenClrDataEnumMemoryRegionsCallback@@6B@
0x18001F1B0: "Wow64RevertWow64FsRedirection" ??_C@_0BO@KOCOEJCM@Wow64RevertWow64FsRedirection?$AA@
0x1800078E0: "public: virtual void __cdecl PssNtWin32LiveSystemProvider::Release(void) __ptr64" ?Release@PssNtWin32LiveSystemProvider@@UEAAXXZ
0x18001FD38: "PathIsDirectoryA" ??_C@_0BB@POIALEKO@PathIsDirectoryA?$AA@
0x18001EE80: "RtlFindMessage" ??_C@_0P@NNIFCLKJ@RtlFindMessage?$AA@
0x1800088F0: "public: virtual unsigned long __cdecl Win32LiveSystemProvider::ResumeThread(void * __ptr64) __ptr64" ?ResumeThread@Win32LiveSystemProvider@@UEAAKPEAX@Z
0x18001BB90: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x18001B9E8: "__cdecl _imp_HeapReAlloc" __imp_HeapReAlloc
0x18000F440: "public: virtual long __cdecl GenClrDataTarget::ReadVirtual(unsigned __int64,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64) __ptr64" ?ReadVirtual@GenClrDataTarget@@UEAAJ_KPEAEIPEAI@Z
0x18001CFB8: "api-ms-win-core-timezone-l1-1-0." ??_C@_0CE@FHNIMKPB@api?9ms?9win?9core?9timezone?9l1?91?90?4@
0x18001FAA0: "CloseDesktop" ??_C@_0N@IKNGKJFJ@CloseDesktop?$AA@
0x180025E30: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreLocalizationCallNames" ?g_CoreLocalizationCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180019BE8: "__cdecl _scrt_dllmain_crt_thread_attach" __scrt_dllmain_crt_thread_attach
0x18001A37C: "__cdecl o__seh_filter_dll" _o__seh_filter_dll
0x18001CAB8: "Invalid exception record size (0" ??_C@_0CF@NOIMGEHL@Invalid?5exception?5record?5size?5?$CI0@
0x18001A31A: "__cdecl _std_type_info_destroy_list" __std_type_info_destroy_list
0x1800277E0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreWinRTCallNames" ?g_CoreWinRTCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180008030: "public: virtual long __cdecl Win32LiveSystemProvider::GetOsCsdString(unsigned short * __ptr64,unsigned long) __ptr64" ?GetOsCsdString@Win32LiveSystemProvider@@UEAAJPEAGK@Z
0x18001820C: GetProcessIptTrace
0x18000A5D0: "protected: long __cdecl Win32LiveSystemProvider::TibGetThreadTebInfo(void * __ptr64,unsigned __int64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64) __ptr64" ?TibGetThreadTebInfo@Win32LiveSystemProvider@@IEAAJPEAX_KPEA_K2222@Z
0x18001D1A0: "api-ms-win-core-processthreads-l" ??_C@_0CK@BJHFLDDO@api?9ms?9win?9core?9processthreads?9l@
0x18001C0C8: "dbgcore" ??_C@_1BA@LGEEBNDG@?$AAd?$AAb?$AAg?$AAc?$AAo?$AAr?$AAe?$AA?$AA@
0x180012D90: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::QueryVirtual(void * __ptr64,unsigned __int64,struct _MINIDUMP_MEMORY_INFO * __ptr64) __ptr64" ?QueryVirtual@PssNtWin32LiveSystemProvider@@UEAAJPEAX_KPEAU_MINIDUMP_MEMORY_INFO@@@Z
0x18001A570: "__cdecl _chkstk" __chkstk
0x180018180: "[thunk]:public: virtual void * __ptr64 __cdecl NtWin32LiveSystemProvider::`vector deleting destructor'`adjustor{8}' (unsigned int) __ptr64" ??_ENtWin32LiveSystemProvider@@W7EAAPEAXI@Z
0x180009840: "public: virtual long __cdecl Win32LiveSystemProvider::EnumPebMemory(void * __ptr64,unsigned long,unsigned __int64,unsigned long,class MiniDumpProviderCallbacks * __ptr64) __ptr64" ?EnumPebMemory@Win32LiveSystemProvider@@UEAAJPEAXK_KKPEAVMiniDumpProviderCallbacks@@@Z
0x1800201B0: "OpenSCManagerA" ??_C@_0P@KIBOOHEE@OpenSCManagerA?$AA@
0x18001F8D0: "api-ms-win-core-file-l1-2-1.dll" ??_C@_0CA@GDCMMPHC@api?9ms?9win?9core?9file?9l1?92?91?4dll?$AA@
0x18001C480: "WriteDirectoryEntry.Write(0x%x) " ??_C@_0CP@IAAFCFLE@WriteDirectoryEntry?4Write?$CI0x?$CFx?$CJ?5@
0x18001F0E0: "Process32Next" ??_C@_0O@LGJLFMBH@Process32Next?$AA@
0x1800118E4: "struct _VA_RANGE * __ptr64 __cdecl GenFindMemoryBlock(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned long)" ?GenFindMemoryBlock@@YAPEAU_VA_RANGE@@PEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@_KK@Z
0x18001DA58: "GenReadTlsDirectory.Read(0x%I64x" ??_C@_0DG@HJBOMPAL@GenReadTlsDirectory?4Read?$CI0x?$CFI64x@
0x18000B3B0: "public: virtual void __cdecl Win32LiveAllocationProvider::Free(void * __ptr64) __ptr64" ?Free@Win32LiveAllocationProvider@@UEAAXPEAX@Z
0x1800088D0: "public: virtual unsigned long __cdecl Win32LiveSystemProvider::GetCurrentThreadId(void) __ptr64" ?GetCurrentThreadId@Win32LiveSystemProvider@@UEAAKXZ
0x18001BAB0: "__cdecl _imp_UnmapViewOfFile" __imp_UnmapViewOfFile
0x18001ED70: "NtRemoveProcessDebug" ??_C@_0BF@DGADPHCG@NtRemoveProcessDebug?$AA@
0x18001D2B0: "sysarm32" ??_C@_1BC@PNHANHEA@?$AAs?$AAy?$AAs?$AAa?$AAr?$AAm?$AA3?$AA2?$AA?$AA@
0x18001F5B0: "DebugActiveProcess" ??_C@_0BD@IADKGHBM@DebugActiveProcess?$AA@
0x18001CB30: "GetSystemType.GetCpuType failed," ??_C@_0CI@HJIONFCD@GetSystemType?4GetCpuType?5failed?0@
0x18001E4A8: "GenWriteHandleOperations.Seek(0x" ??_C@_0DD@HLNPNGNL@GenWriteHandleOperations?4Seek?$CI0x@
0x1800201E0: "OpenServiceW" ??_C@_0N@NDJOABJF@OpenServiceW?$AA@
0x18001C3F0: "WriteTokenInformation.Write(%d,%" ??_C@_0DB@MDJGPNKB@WriteTokenInformation?4Write?$CI?$CFd?0?$CF@
0x18001BA98: api-ms-win-core-localregistry-l1-1-0_NULL_THUNK_DATA
0x18001D528: "api-ms-win-core-psapi-obsolete-l" ??_C@_0CK@CDBLCIBB@api?9ms?9win?9core?9psapi?9obsolete?9l@
0x18000298C: "long __cdecl WriteTokenInformation(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteTokenInformation@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x18001FE20: "api-ms-win-shlwapi-ie-l1-1-0.dll" ??_C@_0CB@LCNEADPN@api?9ms?9win?9shlwapi?9ie?9l1?91?90?4dll@
0x180002C2C: "long __cdecl WriteProcessVmCounters(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?WriteProcessVmCounters@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x18000AF50: "public: virtual long __cdecl Win32LiveSystemProvider::GetProcessIptTrace(void * __ptr64,void * __ptr64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetProcessIptTrace@Win32LiveSystemProvider@@UEAAJPEAXPEAPEAXPEAK@Z
0x1800187D4: "public: __cdecl MiniDumpOsImports::~MiniDumpOsImports(void) __ptr64" ??1MiniDumpOsImports@@QEAA@XZ
0x1800172D0: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetOsInfo(unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64) __ptr64" ?GetOsInfo@NtWin32LiveSystemProvider@@UEAAJPEAK000PEAG11@Z
0x18001BD18: "__cdecl _xp_z" __xp_z
0x18001C860: "WriteFullMemory.Memory.Read(0x%I" ??_C@_0EB@OPHELMDL@WriteFullMemory?4Memory?4Read?$CI0x?$CFI@
0x18001C4E0: "Thread(0x%x) callback returned F" ??_C@_0CF@EDLHEOIO@Thread?$CI0x?$CFx?$CJ?5callback?5returned?5F@
0x180009C94: "private: long __cdecl Win32LiveSystemProvider::NtVerifyMicrosoftSignature(void * __ptr64) __ptr64" ?NtVerifyMicrosoftSignature@Win32LiveSystemProvider@@AEAAJPEAX@Z
0x1800136C0: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetThreadContextEx(void * __ptr64,void * __ptr64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned long,bool) __ptr64" ?GetThreadContextEx@PssNtWin32LiveSystemProvider@@UEAAJPEAX00KPEA_K11K_N@Z
0x180007C30: "public: virtual long __cdecl Win32LiveSystemProvider::GetCpuPowerInfo(unsigned long,struct _PROCESSOR_POWER_INFORMATION * __ptr64,unsigned long * __ptr64) __ptr64" ?GetCpuPowerInfo@Win32LiveSystemProvider@@UEAAJKPEAU_PROCESSOR_POWER_INFORMATION@@PEAK@Z
0x180027600: "struct _DYNAMIC_CALL_NAME volatile * volatile g_ApiMsWinCoreComL1CallNames" ?g_ApiMsWinCoreComL1CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001BB58: "__cdecl _imp_MultiByteToWideChar" __imp_MultiByteToWideChar
0x18001EF98: "RtlLocateExtendedFeature" ??_C@_0BJ@FFEDDLPL@RtlLocateExtendedFeature?$AA@
0x180009660: "public: virtual long __cdecl GenClrDataTarget::FreeVirtual(unsigned __int64,unsigned int,unsigned int) __ptr64" ?FreeVirtual@GenClrDataTarget@@UEAAJ_KII@Z
0x18001F438: "FillConsoleOutputAttribute" ??_C@_0BL@KOFJOHJA@FillConsoleOutputAttribute?$AA@
0x18001ECD8: "DbgUiSetThreadDebugObject" ??_C@_0BK@JMIJBBFL@DbgUiSetThreadDebugObject?$AA@
0x18001EBC0: "NtQueryInformationThread" ??_C@_0BJ@HKKELGGC@NtQueryInformationThread?$AA@
0x180025200: "struct _CORE_LOCALIZATION_CALLS volatile g_CoreLocalizationCalls" ?g_CoreLocalizationCalls@@3U_CORE_LOCALIZATION_CALLS@@C
0x18001BB48: api-ms-win-core-profile-l1-1-0_NULL_THUNK_DATA
0x1800207F8: "__cdecl _rtc_tzz" __rtc_tzz
0x18001BD30: "__cdecl _guard_fids_table" __guard_fids_table
0x18001EC28: "IsWow64Process2" ??_C@_0BA@JBBGLKFP@IsWow64Process2?$AA@
0x180025CB0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_SecurityLsaLookupCallNames" ?g_SecurityLsaLookupCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180009660: "public: virtual long __cdecl Win32LiveSystemProvider::EnumFunctionTableEntryMemory(unsigned __int64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?EnumFunctionTableEntryMemory@Win32LiveSystemProvider@@UEAAJ_KPEAXKPEA_KPEAK@Z
0x1800063EC: "long __cdecl DetermineSystemProvider(class MiniDumpAllocationProvider * __ptr64,class MiniDumpStatusProvider * __ptr64,void * __ptr64,struct _MINIDUMP_CALLBACK_INFORMATION * __ptr64 const,class MiniDumpSystemProvider * __ptr64 * __ptr64)" ?DetermineSystemProvider@@YAJPEAVMiniDumpAllocationProvider@@PEAVMiniDumpStatusProvider@@PEAXQEAU_MINIDUMP_CALLBACK_INFORMATION@@PEAPEAVMiniDumpSystemProvider@@@Z
0x18001D2F8: "MINIDUMP_AUXILIARY_PROVIDER" ??_C@_0BM@OIJLPNIL@MINIDUMP_AUXILIARY_PROVIDER?$AA@
0x18000B200: "public: virtual void __cdecl CallbackOutputProvider::Release(void) __ptr64" ?Release@CallbackOutputProvider@@UEAAXXZ
0x180007A40: "public: virtual long __cdecl Win32LiveSystemProvider::CloseToken(void * __ptr64) __ptr64" ?CloseToken@Win32LiveSystemProvider@@UEAAJPEAX@Z
0x18001B860: "__cdecl load_config_used" _load_config_used
0x18000A47C: "protected: long __cdecl Win32LiveSystemProvider::ProcessThread32Next(void * __ptr64,unsigned long,struct tagTHREADENTRY32 * __ptr64) __ptr64" ?ProcessThread32Next@Win32LiveSystemProvider@@IEAAJPEAXKPEAUtagTHREADENTRY32@@@Z
0x18001FCB0: "VariantInit" ??_C@_0M@BBHOMDMB@VariantInit?$AA@
0x18001F5C8: "WaitForDebugEvent" ??_C@_0BC@IMLKCIIP@WaitForDebugEvent?$AA@
0x18001CE20: "CreateToolhelp32Snapshot" ??_C@_0BJ@JEFKDHMD@CreateToolhelp32Snapshot?$AA@
0x18001CEC0: "IsProcessorFeaturePresent" ??_C@_0BK@NHEOCAHP@IsProcessorFeaturePresent?$AA@
0x18000B5C0: "int __cdecl GenUpdatePdbNameInCvRecord(void * __ptr64,unsigned long,int)" ?GenUpdatePdbNameInCvRecord@@YAHPEAXKH@Z
0x18001C6F0: "WriteMemoryInfo.Write(0x%x) fail" ??_C@_0CL@DDGAMICD@WriteMemoryInfo?4Write?$CI0x?$CFx?$CJ?5fail@
0x18000B96C: "int __cdecl GenCheckCancel(struct _MINIDUMP_STATE * __ptr64)" ?GenCheckCancel@@YAHPEAU_MINIDUMP_STATE@@@Z
0x180020058: "CreateServiceA" ??_C@_0P@EOCCPLHH@CreateServiceA?$AA@
0x180020228: "CryptAcquireContextW" ??_C@_0BF@JHHBLAOM@CryptAcquireContextW?$AA@
0x180016ED0: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumTebMemory(void * __ptr64,void * __ptr64,unsigned long,unsigned __int64,unsigned long,class MiniDumpProviderCallbacks * __ptr64) __ptr64" ?EnumTebMemory@NtWin32LiveSystemProvider@@UEAAJPEAX0K_KKPEAVMiniDumpProviderCallbacks@@@Z
0x18001CD80: "Write.Start failed, 0x%08x" ??_C@_0BL@FDKOADHO@Write?4Start?5failed?0?50x?$CF08x?$AA@
0x18001DB78: "Unable to add directory %x from " ??_C@_0DJ@PMKDCFIN@Unable?5to?5add?5directory?5?$CFx?5from?5@
0x18001A3DC: swprintf_s
0x180007A40: "public: virtual long __cdecl Win32LiveSystemProvider::EnumHandles(unsigned __int64 * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned short * __ptr64,unsigned long,unsigned short * __ptr64,unsigned long) __ptr64" ?EnumHandles@Win32LiveSystemProvider@@UEAAJPEA_KPEAK111PEAGK2K@Z
0x18000AE20: "protected: static unsigned long __cdecl Win32LiveSystemProvider::HandleOpCb(void * __ptr64,void * __ptr64,unsigned long * __ptr64)" ?HandleOpCb@Win32LiveSystemProvider@@KAKPEAX0PEAK@Z
0x18001D5B8: "GetModuleFileNameExW" ??_C@_0BF@PJJPMHMO@GetModuleFileNameExW?$AA@
0x18001E7B8: "ntdll.dll" ??_C@_09FLKFJBLM@ntdll?4dll?$AA@
0x1800259D8: "struct _WINTRUST_CALLS volatile g_WintrustCalls" ?g_WintrustCalls@@3U_WINTRUST_CALLS@@C
0x18001BD00: "__cdecl _scrt_stdio_legacy_msvcrt_compatibility" __scrt_stdio_legacy_msvcrt_compatibility
0x180011CB8: "long __cdecl GenAddMemoryBlock(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,enum MEMBLOCK_TYPE,enum MEMBLOCK_FILTER_TYPE,unsigned __int64,unsigned long)" ?GenAddMemoryBlock@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@W4MEMBLOCK_TYPE@@W4MEMBLOCK_FILTER_TYPE@@_KK@Z
0x180007950: "public: virtual long __cdecl Win32LiveSystemProvider::GetCpuType(unsigned long * __ptr64,int * __ptr64) __ptr64" ?GetCpuType@Win32LiveSystemProvider@@UEAAJPEAKPEAH@Z
0x180008CB0: "public: virtual long __cdecl Win32LiveSystemProvider::GetProcessTimes(void * __ptr64,struct _FILETIME * __ptr64,struct _FILETIME * __ptr64,struct _FILETIME * __ptr64) __ptr64" ?GetProcessTimes@Win32LiveSystemProvider@@UEAAJPEAXPEAU_FILETIME@@11@Z
0x18001C140: "GetFileVersionInfoSizeExW" ??_C@_0BK@NCKKICFJ@GetFileVersionInfoSizeExW?$AA@
0x18001BA78: "__cdecl _imp_RegQueryValueExA" __imp_RegQueryValueExA
0x180002B60: "long __cdecl WriteSystemMemoryInformation(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?WriteSystemMemoryInformation@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x18001FAB0: "CLSIDFromString" ??_C@_0BA@OCNJAMDG@CLSIDFromString?$AA@
0x18001C1B0: "WriteAtOffset.Write(0x%x) failed" ??_C@_0CJ@CACIFGON@WriteAtOffset?4Write?$CI0x?$CFx?$CJ?5failed@
0x18001F190: "Wow64DisableWow64FsRedirection" ??_C@_0BP@OODKCJPP@Wow64DisableWow64FsRedirection?$AA@
0x180020198: "LookupAccountSidW" ??_C@_0BC@IDGHENMJ@LookupAccountSidW?$AA@
0x18000205C: "long __cdecl WriteModuleList(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteModuleList@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x1800201F0: "StartServiceA" ??_C@_0O@IKOPFGDH@StartServiceA?$AA@
0x18001F2D8: "ConvertThreadToFiber" ??_C@_0BF@JGFDIEAC@ConvertThreadToFiber?$AA@
0x180025260: "struct _EVENTING_PROVIDER_CALLS volatile g_EventingProviderCalls" ?g_EventingProviderCalls@@3U_EVENTING_PROVIDER_CALLS@@C
0x180019F20: "__cdecl _scrt_get_dyn_tls_init_callback" __scrt_get_dyn_tls_init_callback
0x180026580: "struct _DYNAMIC_CALLS_DESC volatile g_EventingProviderCallsDesc" ?g_EventingProviderCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001DC10: "GenAllocateModuleObject.GetVersi" ??_C@_0EA@EJOJGGA@GenAllocateModuleObject?4GetVersi@
0x18001F500: "GetCommMask" ??_C@_0M@FNGIKMPI@GetCommMask?$AA@
0x180007910: "public: virtual long __cdecl Win32LiveSystemProvider::GetCurrentTimeDate(unsigned long * __ptr64) __ptr64" ?GetCurrentTimeDate@Win32LiveSystemProvider@@UEAAJPEAK@Z
0x18001BA40: "__cdecl _imp_DisableThreadLibraryCalls" __imp_DisableThreadLibraryCalls
0x18001BCB0: "__cdecl _imp_NtClose" __imp_NtClose
0x18001EA60: "Software\Microsoft\Windows NT\Cu" ??_C@_0EE@FKLICAIJ@Software?2Microsoft?2Windows?5NT?2Cu@
0x18001BBE8: "__cdecl _imp__strlwr_s" __imp__strlwr_s
0x180020410: "api-ms-win-security-lsalookup-l2" ??_C@_0CJ@CMNNPAJI@api?9ms?9win?9security?9lsalookup?9l2@
0x18001CC80: "Invalid CPU type (0x%x)" ??_C@_0BI@LHFMIAHO@Invalid?5CPU?5type?5?$CI0x?$CFx?$CJ?$AA@
0x18001BAC8: "__cdecl _imp_VirtualQueryEx" __imp_VirtualQueryEx
0x18001FD10: "SysStringLen" ??_C@_0N@OIJDDAAM@SysStringLen?$AA@
0x18001E9D8: "RtlGetVersion" ??_C@_0O@JGECDCHJ@RtlGetVersion?$AA@
0x18001BCA0: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x18001BB40: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x18001F938: "api-ms-win-core-io-l1-1-1.dll" ??_C@_0BO@NMCFFILP@api?9ms?9win?9core?9io?9l1?91?91?4dll?$AA@
0x1800219C8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-crt-string-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-crt-string-l1-1-0
0x18001FDE8: "SHCreateStreamOnFileW" ??_C@_0BG@DAGOPAOG@SHCreateStreamOnFileW?$AA@
0x18001F300: "CreateNamedPipeA" ??_C@_0BB@GOPFAJNA@CreateNamedPipeA?$AA@
0x180007E40: "public: virtual void __cdecl Win32LiveSystemProvider::GetFunctionTableSizes(unsigned long * __ptr64,unsigned long * __ptr64) __ptr64" ?GetFunctionTableSizes@Win32LiveSystemProvider@@UEAAXPEAK0@Z
0x180027680: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreIoCallNames" ?g_CoreIoCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180026270: "struct _DYNAMIC_CALL_NAME volatile * volatile g_ShlWapiCallNames" ?g_ShlWapiCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001D6C0: "FreeDumpStreams" ??_C@_0BA@KAEIEAGB@FreeDumpStreams?$AA@
0x18001E878: "NtQueryInformationProcess" ??_C@_0BK@EGDDIFMK@NtQueryInformationProcess?$AA@
0x18001A440: "__cdecl _acrt_uninitialize_critical" __acrt_uninitialize_critical
0x18001D868: "GenAllocateThreadObject.Open(0x%" ??_C@_0DC@IALHANIM@GenAllocateThreadObject?4Open?$CI0x?$CF@
0x18001BAA8: "__cdecl _imp_VirtualAlloc" __imp_VirtualAlloc
0x18001E7E0: "Mutant" ??_C@_1O@FBKOCLFA@?$AAM?$AAu?$AAt?$AAa?$AAn?$AAt?$AA?$AA@
0x180026380: "struct _DYNAMIC_CALLS_DESC volatile g_WintrustCallsDesc" ?g_WintrustCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180002CFC: "long __cdecl WriteThreadNames(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteThreadNames@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x18001A3AC: free
0x18001F290: "CreateWaitableTimerW" ??_C@_0BF@MGPDPGAO@CreateWaitableTimerW?$AA@
0x18001FC68: "SysAllocStringLen" ??_C@_0BC@LFAKAPMA@SysAllocStringLen?$AA@
0x1800202A0: "CryptReleaseContext" ??_C@_0BE@FBIJLPPP@CryptReleaseContext?$AA@
0x18001BBC0: "__cdecl _imp__initialize_narrow_environment" __imp__initialize_narrow_environment
0x18000B7F8: "int __cdecl GenExecuteIncludeThreadCallback(struct _MINIDUMP_STATE * __ptr64,unsigned long,unsigned long * __ptr64)" ?GenExecuteIncludeThreadCallback@@YAHPEAU_MINIDUMP_STATE@@KPEAK@Z
0x180011210: "public: virtual long __cdecl CallbackOutputProvider::WriteAll(void * __ptr64,unsigned long) __ptr64" ?WriteAll@CallbackOutputProvider@@UEAAJPEAXK@Z
0x180023678: "struct _INTERNAL_PROCESS * __ptr64 __ptr64 g_StackProviderCallBackProcess" ?g_StackProviderCallBackProcess@@3PEAU_INTERNAL_PROCESS@@EA
0x180025278: "struct _VERIFIER_CALLS volatile g_VerifierCalls" ?g_VerifierCalls@@3U_VERIFIER_CALLS@@C
0x18001BA18: "__cdecl _imp_InitializeSListHead" __imp_InitializeSListHead
0x18001BCC0: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x18001E710: "PssWalkMarkerTell" ??_C@_0BC@KCCOHLEH@PssWalkMarkerTell?$AA@
0x18001A370: "__cdecl purecall" _purecall
0x180018894: "public: long __cdecl MiniDumpOsImports::NtQueryInformationThread(void * __ptr64,enum _THREADINFOCLASS,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?NtQueryInformationThread@MiniDumpOsImports@@QEAAJPEAXW4_THREADINFOCLASS@@0KPEAK@Z
0x18001F4C0: "CopyFileExW" ??_C@_0M@HGFIGBEM@CopyFileExW?$AA@
0x18000B0B8: MiniDumpCreateLiveSystemProvider
0x1800265B0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreProcessEnvironmentCallsDesc" ?g_CoreProcessEnvironmentCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180018604: RtlpMrdataUnlock
0x180023040: "unsigned __int64 `__local_stdio_printf_options'::`2'::_OptionsStorage" ?_OptionsStorage@?1??__local_stdio_printf_options@@9@4_KA
0x180017118: "protected: void __cdecl NtWin32LiveSystemProvider::TranslateNtPathName(unsigned short * __ptr64) __ptr64" ?TranslateNtPathName@NtWin32LiveSystemProvider@@IEAAXPEAG@Z
0x18001FD80: "PathFindNextComponentW" ??_C@_0BH@KBAGPBKG@PathFindNextComponentW?$AA@
0x1800096A0: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x18001FA40: "Secur32.dll" ??_C@_0M@BCNENKKF@Secur32?4dll?$AA@
0x180025230: "struct _SHLWAPI_IE_CALLS volatile g_ShlwapiIeCalls" ?g_ShlwapiIeCalls@@3U_SHLWAPI_IE_CALLS@@C
0x18001D2E0: "system32" ??_C@_1BC@KMLJNHDN@?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?$AA@
0x18001BC28: "__cdecl _imp_wcsrchr" __imp_wcsrchr
0x1800030E4: "long __cdecl ExecuteCallbacks(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?ExecuteCallbacks@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@@Z
0x18001A440: "__cdecl _scrt_stub_for_acrt_uninitialize" __scrt_stub_for_acrt_uninitialize
0x180009840: "__cdecl _scrt_stub_for_is_c_termination_complete" __scrt_stub_for_is_c_termination_complete
0x180014590: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::QueryMiscInformationEx(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64,struct MISC_EXDATA * __ptr64) __ptr64" ?QueryMiscInformationEx@PssNtWin32LiveSystemProvider@@UEAAJPEAXKPEAK0K1PEAUMISC_EXDATA@@@Z
0x180025120: "struct _CORE_KERNEL32_PRIVATE_CALLS volatile g_CoreKernel32PrivateCalls" ?g_CoreKernel32PrivateCalls@@3U_CORE_KERNEL32_PRIVATE_CALLS@@C
0x180023658: "protected: static int (__cdecl* __ptr64 Win32LiveSystemProvider::s_GetFileVersionInfoExW)(unsigned long,unsigned short const * __ptr64,unsigned long,unsigned long,void * __ptr64)" ?s_GetFileVersionInfoExW@Win32LiveSystemProvider@@1P6AHKPEBGKKPEAX@ZEA
0x180007A40: "public: virtual long __cdecl Win32LiveSystemProvider::EnumHandleObjectInfo(unsigned __int64,unsigned short const * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?EnumHandleObjectInfo@Win32LiveSystemProvider@@UEAAJ_KPEBGKPEAKPEAXK2@Z
0x18001CC28: "Invalid function table entry siz" ??_C@_0CJ@MLABGPDN@Invalid?5function?5table?5entry?5siz@
0x18001D248: "Software\Microsoft\Windows NT\Cu" ??_C@_0CN@OJOMIAJ@Software?2Microsoft?2Windows?5NT?2Cu@
0x18001C220: "WriteStringToPool.Write(0x%x) fa" ??_C@_0CN@HLECOEFF@WriteStringToPool?4Write?$CI0x?$CFx?$CJ?5fa@
0x1800203B0: "api-ms-win-core-registry-private" ??_C@_0CM@OKGLFADJ@api?9ms?9win?9core?9registry?9private@
0x18001D088: "api-ms-win-core-versionansi-l1-1" ??_C@_0CH@HIPGMPLP@api?9ms?9win?9core?9versionansi?9l1?91@
0x18001A326: "__cdecl _stdio_common_vswprintf_s" __stdio_common_vswprintf_s
0x18001F4D0: "MoveFileExW" ??_C@_0M@NIIDHDHA@MoveFileExW?$AA@
0x180013A70: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::StartProcessEnum(void * __ptr64,unsigned long) __ptr64" ?StartProcessEnum@PssNtWin32LiveSystemProvider@@UEAAJPEAXK@Z
0x180021B1C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-interlocked-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-interlocked-l1-1-0
0x180021ACC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0
0x180027040: "struct _DYNAMIC_CALLS_DESC volatile g_CoreUrlCallsDesc" ?g_CoreUrlCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001DE20: "ProcessToken_Groups(0x%08X,%d,%d" ??_C@_0CF@IPFFOHMN@ProcessToken_Groups?$CI0x?$CF08X?0?$CFd?0?$CFd@
0x18001F600: "GetLocaleInfoA" ??_C@_0P@GIFDNDIK@GetLocaleInfoA?$AA@
0x180023680: "struct _MINIDUMP_STATE * __ptr64 __ptr64 g_StackProviderCallBackMiniDump" ?g_StackProviderCallBackMiniDump@@3REAU_MINIDUMP_STATE@@EA
0x18001118C: "unsigned short * __ptr64 __cdecl GenStrCopyNW(unsigned short * __ptr64,unsigned short const * __ptr64,int)" ?GenStrCopyNW@@YAPEAGPEAGPEBGH@Z
0x1800033F4: "long __cdecl WriteSystemInfo(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?WriteSystemInfo@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x18001C6D0: "Memory info stream overflowed" ??_C@_0BO@FEODPLIO@Memory?5info?5stream?5overflowed?$AA@
0x1800277A0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreMiscCallsDesc" ?g_CoreMiscCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001FB00: "CoMarshalInterface" ??_C@_0BD@BFCOEHP@CoMarshalInterface?$AA@
0x18001FB70: "CreateStreamOnHGlobal" ??_C@_0BG@DNLLFOBD@CreateStreamOnHGlobal?$AA@
0x18001D7F0: "GenGetImageSections.GenImageNtHe" ??_C@_0DF@DGJEGKCO@GenGetImageSections?4GenImageNtHe@
0x18001CDD0: "Thread32Next" ??_C@_0N@LDGMJMKG@Thread32Next?$AA@
0x180016FD0: "public: virtual long __cdecl NtWin32LiveSystemProvider::WriteKernelMinidump(void * __ptr64,void * __ptr64,unsigned long,void * __ptr64 * __ptr64,unsigned long,unsigned long) __ptr64" ?WriteKernelMinidump@NtWin32LiveSystemProvider@@UEAAJPEAX0KPEAPEAXKK@Z
0x180015470: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetThreadTebInfo(void * __ptr64,void * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,bool) __ptr64" ?GetThreadTebInfo@NtWin32LiveSystemProvider@@UEAAJPEAX0PEA_KPEAK11111_N@Z
0x18001EB28: "SymRegisterFunctionEntryCallback" ??_C@_0CD@HLBLMOJP@SymRegisterFunctionEntryCallback@
0x18001FF58: "CertGetCertificateContextPropert" ??_C@_0CC@LPOHJFGK@CertGetCertificateContextPropert@
0x180026860: "struct _DYNAMIC_CALLS_DESC volatile g_CoreVersionCallsDesc" ?g_CoreVersionCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x1800096A0: "public: virtual void __cdecl Win32LiveSystemProvider::FinishHandleEnum(void) __ptr64" ?FinishHandleEnum@Win32LiveSystemProvider@@UEAAXXZ
0x18001F668: "CopyFileW" ??_C@_09LILHBHJJ@CopyFileW?$AA@
0x18000B3E0: "public: virtual void __cdecl NullStatusProvider::Status(unsigned long,char const * __ptr64,...) __ptr64" ?Status@NullStatusProvider@@UEAAXKPEBDZZ
0x18001A302: "__cdecl initterm_e" _initterm_e
0x18000FE54: "long __cdecl GenGetProcessInfo(unsigned long,struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64 * __ptr64,struct _LIST_ENTRY * __ptr64)" ?GenGetProcessInfo@@YAJKPEAU_MINIDUMP_STATE@@PEAPEAU_INTERNAL_PROCESS@@PEAU_LIST_ENTRY@@@Z
0x180019EC0: "__cdecl _scrt_release_startup_lock" __scrt_release_startup_lock
0x180014FE0: "public: virtual long __cdecl NtWin32LiveSystemProvider::Initialize(void) __ptr64" ?Initialize@NtWin32LiveSystemProvider@@UEAAJXZ
0x180027000: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreFileL1CallNames" ?g_CoreFileL1CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180026500: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreFileL2CallNames" ?g_CoreFileL2CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180026730: "struct _DYNAMIC_CALL_NAME volatile * volatile g_ServiceManagementCallNames" ?g_ServiceManagementCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001F738: "GetPackageFullName" ??_C@_0BD@KHEEFJGG@GetPackageFullName?$AA@
0x18001D518: "psapi.dll" ??_C@_09LOPACEED@psapi?4dll?$AA@
0x18000C744: "long __cdecl GenGetImageSections(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_MODULE * __ptr64,unsigned long)" ?GenGetImageSections@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_MODULE@@K@Z
0x18001F610: "GetUserGeoID" ??_C@_0N@HAAENANE@GetUserGeoID?$AA@
0x18001F4E0: "CancelIo" ??_C@_08KENEPFL@CancelIo?$AA@
0x18001D4A8: "CLRDataCreateInstance" ??_C@_0BG@IKNMOAKL@CLRDataCreateInstance?$AA@
0x180025EF0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_Secur32CallNames" ?g_Secur32CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x1800275A0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CorePsapiCallNames" ?g_CorePsapiCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180019CD4: "__cdecl _scrt_dllmain_uninitialize_critical" __scrt_dllmain_uninitialize_critical
0x18001BCC8: ntdll_NULL_THUNK_DATA
0x18001BC50: "__cdecl _imp_memcpy" __imp_memcpy
0x18000F280: "public: virtual long __cdecl GenClrDataTarget::QueryInterface(struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?QueryInterface@GenClrDataTarget@@UEAAJAEBU_GUID@@PEAPEAX@Z
0x18001ED10: "NtCreateFile" ??_C@_0N@KPMLACHP@NtCreateFile?$AA@
0x180026430: "struct _DYNAMIC_CALL_NAME volatile * volatile g_DownlevelShlwapiL2CallNames" ?g_DownlevelShlwapiL2CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180027700: "struct _DYNAMIC_CALL_NAME volatile * volatile g_DownlevelShlwapiL1CallNames" ?g_DownlevelShlwapiL1CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180012750: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::Initialize(void) __ptr64" ?Initialize@PssNtWin32LiveSystemProvider@@UEAAJXZ
0x18001E950: "NtOpenThreadToken" ??_C@_0BC@PBPJBNCP@NtOpenThreadToken?$AA@
0x18000B220: "public: virtual long __cdecl Win32FileOutputProvider::Seek(unsigned long,__int64,unsigned __int64 * __ptr64) __ptr64" ?Seek@Win32FileOutputProvider@@UEAAJK_JPEA_K@Z
0x18001CC00: "Invalid function table size (0x%" ??_C@_0CD@JDNFEOIL@Invalid?5function?5table?5size?5?$CI0x?$CF@
0x1800257B0: "struct _CORE_PROCESSTHREADS_CALLS volatile g_CoreProcessThreadsCalls" ?g_CoreProcessThreadsCalls@@3U_CORE_PROCESSTHREADS_CALLS@@C
0x18001FF00: "CertFreeCertificateChain" ??_C@_0BJ@EPAPOMOE@CertFreeCertificateChain?$AA@
0x18001B620: "const PssNtWin32LiveSystemProvider::`vftable'{for `MiniDumpVmHookedProvider'}" ??_7PssNtWin32LiveSystemProvider@@6BMiniDumpVmHookedProvider@@@
0x18001A440: "__cdecl _scrt_stub_for_acrt_uninitialize_critical" __scrt_stub_for_acrt_uninitialize_critical
0x180026180: "struct _DYNAMIC_CALLS_DESC volatile g_SspiCliCallsDesc" ?g_SspiCliCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180014D00: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetProcessIptTrace(void * __ptr64,void * __ptr64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetProcessIptTrace@PssNtWin32LiveSystemProvider@@UEAAJPEAXPEAPEAXPEAK@Z
0x18001ED88: "NtResumeThread" ??_C@_0P@JDJEHDNH@NtResumeThread?$AA@
0x1800111E0: "public: virtual long __cdecl CallbackOutputProvider::Start(unsigned __int64) __ptr64" ?Start@CallbackOutputProvider@@UEAAJ_K@Z
0x180025C58: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreKernel32PrivateCallNames" ?g_CoreKernel32PrivateCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001F548: "SetCommMask" ??_C@_0M@FCHGHKHL@SetCommMask?$AA@
0x180021AE0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0
0x1800161C0: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumFunctionTableEntryMemory(unsigned __int64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?EnumFunctionTableEntryMemory@NtWin32LiveSystemProvider@@UEAAJ_KPEAXKPEA_KPEAK@Z
0x18000F7C0: "public: virtual long __cdecl GenClrDataEnumMemoryRegionsCallback::UpdateMemoryRegion(unsigned __int64,unsigned int,unsigned char * __ptr64) __ptr64" ?UpdateMemoryRegion@GenClrDataEnumMemoryRegionsCallback@@UEAAJ_KIPEAE@Z
0x18001C698: "WriteMemoryInfo.QueryVirtual(0x%" ??_C@_0DF@HALMFNL@WriteMemoryInfo?4QueryVirtual?$CI0x?$CF@
0x18001BC48: "__cdecl _imp___CxxFrameHandler3" __imp___CxxFrameHandler3
0x18001B388: "const GenMiniDumpProviderCallbacks::`vftable'" ??_7GenMiniDumpProviderCallbacks@@6B@
0x180023010: "__cdecl _security_cookie" __security_cookie
0x18001C160: "GetFileVersionInfoExW" ??_C@_0BG@GEGOAKFF@GetFileVersionInfoExW?$AA@
0x18001BA70: "__cdecl _imp_RegQueryValueExW" __imp_RegQueryValueExW
0x180026890: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreJobL2CallNames" ?g_CoreJobL2CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001DFD0: "GenGetHandleData.Start(0x%x) fai" ??_C@_0CM@EOCBACCC@GenGetHandleData?4Start?$CI0x?$CFx?$CJ?5fai@
0x18001A570: "__cdecl alloca_probe" _alloca_probe
0x18001EE90: "RtlFreeUnicodeString" ??_C@_0BF@GENHDPCD@RtlFreeUnicodeString?$AA@
0x18001F0C0: "Process32First" ??_C@_0P@ILGHDLOE@Process32First?$AA@
0x18001CB88: "ARM64" ??_C@_1M@INPPMIAA@?$AAA?$AAR?$AAM?$AA6?$AA4?$AA?$AA@
0x180006D9C: "public: virtual void * __ptr64 __cdecl Win32LiveSystemProvider::`scalar deleting destructor'(unsigned int) __ptr64" ??_GWin32LiveSystemProvider@@UEAAPEAXI@Z
0x18001FC90: "VariantClear" ??_C@_0N@HKBLDJLE@VariantClear?$AA@
0x18000F6E0: "public: virtual long __cdecl GenClrDataTarget::GetExceptionThreadID(unsigned int * __ptr64) __ptr64" ?GetExceptionThreadID@GenClrDataTarget@@UEAAJPEAI@Z
0x180019F40: "__cdecl _scrt_fastfail" __scrt_fastfail
0x18001BC38: "__cdecl _imp__o___stdio_common_vswprintf_s" __imp__o___stdio_common_vswprintf_s
0x1800265E0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_Ole32CallNames" ?g_Ole32CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001EB08: "SymInitialize" ??_C@_0O@MCMFENKA@SymInitialize?$AA@
0x18000CC3C: "long __cdecl GenAllocateThreadObject(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned long,unsigned long,struct _INTERNAL_THREAD * __ptr64 * __ptr64)" ?GenAllocateThreadObject@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@KKPEAPEAU_INTERNAL_THREAD@@@Z
0x1800200A0: "EnumServicesStatusExW" ??_C@_0BG@FNODJM@EnumServicesStatusExW?$AA@
0x18001D6E8: "Realloc(0x%x) failed" ??_C@_0BF@DLBPIGAD@Realloc?$CI0x?$CFx?$CJ?5failed?$AA@
0x1800219B4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-crt-runtime-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-crt-runtime-l1-1-0
0x18001B9D0: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x18001D290: "\" ??_C@_01KICIPPFI@?2?$AA@
0x18001EEC0: "RtlInitUnicodeString" ??_C@_0BF@EKFKPNAI@RtlInitUnicodeString?$AA@
0x18000B490: "public: virtual void * __ptr64 __cdecl GenMiniDumpProviderCallbacks::AllocMemory(unsigned long) __ptr64" ?AllocMemory@GenMiniDumpProviderCallbacks@@UEAAPEAXK@Z
0x18001C748: "WriteFullMemory.QueryVirtual(0x%" ??_C@_0DO@BNEGOCAG@WriteFullMemory?4QueryVirtual?$CI0x?$CF@
0x18000576C: "long __cdecl GetSystemType(struct _MINIDUMP_STATE * __ptr64)" ?GetSystemType@@YAJPEAU_MINIDUMP_STATE@@@Z
0x18001DAD0: "GenReadTlsDirectory.Index(0x%I64" ??_C@_0DH@FPCGLCA@GenReadTlsDirectory?4Index?$CI0x?$CFI64@
0x180021A04: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x18001BA20: api-ms-win-core-interlocked-l1-1-0_NULL_THUNK_DATA
0x180015E00: "public: virtual long __cdecl NtWin32LiveSystemProvider::EnumModules(unsigned __int64 * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?EnumModules@NtWin32LiveSystemProvider@@UEAAJPEA_KPEAGK@Z
0x18001BC58: api-ms-win-crt-private-l1-1-0_NULL_THUNK_DATA
0x1800203E0: "api-ms-win-security-cryptoapi-l1" ??_C@_0CJ@HPJIBNOF@api?9ms?9win?9security?9cryptoapi?9l1@
0x18001D338: "WTHelperProvDataFromStateData" ??_C@_0BO@OEKMNOJM@WTHelperProvDataFromStateData?$AA@
0x18001132C: "public: struct _VA_RANGE * __ptr64 __cdecl MiniFixedAllocator<struct _VA_RANGE>::Alloc(void) __ptr64" ?Alloc@?$MiniFixedAllocator@U_VA_RANGE@@@@QEAAPEAU_VA_RANGE@@XZ
0x18001FB88: "CoAllowSetForegroundWindow" ??_C@_0BL@EBPAFNEB@CoAllowSetForegroundWindow?$AA@
0x180025128: "struct _CORE_IO_CALLS volatile g_CoreIoCalls" ?g_CoreIoCalls@@3U_CORE_IO_CALLS@@C
0x1800202B8: "EventRegister" ??_C@_0O@BAMBGLIE@EventRegister?$AA@
0x18000F360: "public: virtual long __cdecl GenClrDataTarget::GetImageBase(unsigned short const * __ptr64,unsigned __int64 * __ptr64) __ptr64" ?GetImageBase@GenClrDataTarget@@UEAAJPEBGPEA_K@Z
0x18001D670: "GetFileVersionInfoA" ??_C@_0BE@JIHADGJK@GetFileVersionInfoA?$AA@
0x18001E598: "__cdecl GUID_2d37c5e2_6b37_4911_b54d_b1b2d7ab795c" _GUID_2d37c5e2_6b37_4911_b54d_b1b2d7ab795c
0x180025CF0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_DownlevelKernel32L2CallNames" ?g_DownlevelKernel32L2CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001BC40: "__cdecl _imp__o___std_type_info_destroy_list" __imp__o___std_type_info_destroy_list
0x18001E000: "GenGetProcessInfo.Start(0x%x) fa" ??_C@_0CN@BJFJAFOC@GenGetProcessInfo?4Start?$CI0x?$CFx?$CJ?5fa@
0x18001A388: "__cdecl strlwr_s" _strlwr_s
0x180025F00: "struct _DYNAMIC_CALL_NAME volatile * volatile g_OleAut32CallNames" ?g_OleAut32CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180025CC0: "struct _DYNAMIC_CALLS_DESC volatile g_CoreCommCallsDesc" ?g_CoreCommCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001ED20: "NtDebugActiveProcess" ??_C@_0BF@LNDHJKNI@NtDebugActiveProcess?$AA@
0x180015AB4: "protected: long __cdecl NtWin32LiveSystemProvider::ReadFunctionTablePointers(void * __ptr64) __ptr64" ?ReadFunctionTablePointers@NtWin32LiveSystemProvider@@IEAAJPEAX@Z
0x180023020: "__cdecl _isa_available" __isa_available
0x180026210: "struct _DYNAMIC_CALLS_DESC volatile g_SecurityBaseCallsDesc" ?g_SecurityBaseCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001DCF0: "GenAllocateModuleObject.GenDebug" ??_C@_0EE@KOFNDCFF@GenAllocateModuleObject?4GenDebug@
0x18001F7B8: "CoUninitialize" ??_C@_0P@EGMOFMDE@CoUninitialize?$AA@
0x18001F878: "api-ms-win-core-processenvironme" ??_C@_0CO@KDHHPIGP@api?9ms?9win?9core?9processenvironme@
0x180026550: "struct _DYNAMIC_CALLS_DESC volatile g_Advapi32CallsDesc" ?g_Advapi32CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001B990: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x18001D0B0: "api-ms-win-core-version-l1-1-0.d" ??_C@_0CD@JLLDDGDN@api?9ms?9win?9core?9version?9l1?91?90?4d@
0x180006790: MiniDumpWriteDump
0x180017540: "public: virtual long __cdecl NtWin32LiveSystemProvider::QueryMiscInformationEx(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64,struct MISC_EXDATA * __ptr64) __ptr64" ?QueryMiscInformationEx@NtWin32LiveSystemProvider@@UEAAJPEAXKPEAK0K1PEAUMISC_EXDATA@@@Z
0x180018990: "int __cdecl ReadProcessMemoryProc64(void * __ptr64,unsigned __int64,void * __ptr64,unsigned long,unsigned long * __ptr64)" ?ReadProcessMemoryProc64@@YAHPEAX_K0KPEAK@Z
0x18001FD20: "PathCreateFromUrlW" ??_C@_0BD@CIMILIGH@PathCreateFromUrlW?$AA@
0x18001BB30: "__cdecl _imp_GetThreadPriority" __imp_GetThreadPriority
0x180019324: "__cdecl _local_stdio_scanf_options" __local_stdio_scanf_options
0x180017F70: "public: virtual long __cdecl NtWin32LiveSystemProvider::QueryProcessVmCounters(void * __ptr64,struct _MINIDUMP_PROCESS_VM_COUNTERS_2 * __ptr64,unsigned long) __ptr64" ?QueryProcessVmCounters@NtWin32LiveSystemProvider@@UEAAJPEAXPEAU_MINIDUMP_PROCESS_VM_COUNTERS_2@@K@Z
0x18001BA88: "__cdecl _imp_RegOpenKeyExA" __imp_RegOpenKeyExA
0x180007A20: "public: virtual long __cdecl Win32LiveSystemProvider::QueryTokenInformation(void * __ptr64,unsigned long,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?QueryTokenInformation@Win32LiveSystemProvider@@UEAAJPEAXK0KPEAK@Z
0x18001BC00: "__cdecl _imp__o_free" __imp__o_free
0x18001BA80: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x18001BBC8: "__cdecl _imp__o__initialize_onexit_table" __imp__o__initialize_onexit_table
0x180023638: "__cdecl _favor" __favor
0x180009840: "public: virtual unsigned long __cdecl GenClrDataTarget::Release(void) __ptr64" ?Release@GenClrDataTarget@@UEAAKXZ
0x180019A24: "__cdecl _security_init_cookie" __security_init_cookie
0x18001DF48: "GenGenTebMemory.TLS(0x%I64x) fai" ??_C@_0CM@ILIKPLAI@GenGenTebMemory?4TLS?$CI0x?$CFI64x?$CJ?5fai@
0x180006B20: "public: virtual void * __ptr64 __cdecl MiniDumpVmHookedProvider::`scalar deleting destructor'(unsigned int) __ptr64" ??_GMiniDumpVmHookedProvider@@UEAAPEAXI@Z
0x180023650: RtlpMrdataSectionOldProtection
0x18001BBA8: "__cdecl _imp__cexit" __imp__cexit
0x180020468: "WNetAddConnection2A" ??_C@_0BE@DCNKFFFA@WNetAddConnection2A?$AA@
0x180018E30: "public: virtual long __cdecl StackProviderDataTarget::GetThreadTeb(unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64) __ptr64" ?GetThreadTeb@StackProviderDataTarget@@UEAAJKPEA_KPEAK@Z
0x180014CC0: "private: static void * __ptr64 __cdecl PssNtWin32LiveSystemProvider::PssAllocRoutine(void * __ptr64,unsigned long)" ?PssAllocRoutine@PssNtWin32LiveSystemProvider@@CAPEAXPEAXK@Z
0x18001B018: "const MiniDumpVmHookedProvider::`vftable'" ??_7MiniDumpVmHookedProvider@@6B@
0x18001D318: "wintrust.dll" ??_C@_0N@EKBBBLPM@wintrust?4dll?$AA@
0x18001F200: "RegisterApplicationRestart" ??_C@_0BL@PGAJLCMF@RegisterApplicationRestart?$AA@
0x18001CF08: "SetCachedSigningLevel" ??_C@_0BG@CGJCIJNF@SetCachedSigningLevel?$AA@
0x18001FCE0: "SafeArrayDestroy" ??_C@_0BB@DFPCNDDL@SafeArrayDestroy?$AA@
0x180020160: "ReadEventLogA" ??_C@_0O@NKKAHEGP@ReadEventLogA?$AA@
0x1800025C8: "long __cdecl WriteMemoryBlocks(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteMemoryBlocks@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x180025E60: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreRegistryPrivateCallNames" ?g_CoreRegistryPrivateCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001BBF0: "__cdecl _imp__o__wcsicmp" __imp__o__wcsicmp
0x18001CF40: "InitializeContext" ??_C@_0BC@HJAILDAB@InitializeContext?$AA@
0x18001F910: "api-ms-win-core-handle-l1-1-0.dl" ??_C@_0CC@LAIBKAIO@api?9ms?9win?9core?9handle?9l1?91?90?4dl@
0x18001CE80: "GetTimeZoneInformation" ??_C@_0BH@MLMPCHGH@GetTimeZoneInformation?$AA@
0x18001D570: "K32GetModuleFileNameExW" ??_C@_0BI@MNNPAFKN@K32GetModuleFileNameExW?$AA@
0x18001E4E0: "GenWriteHandleOperations.List.Wr" ??_C@_0DJ@OCMDOKIJ@GenWriteHandleOperations?4List?4Wr@
0x18001E9B0: "NtQuerySection" ??_C@_0P@GFGDHPCO@NtQuerySection?$AA@
0x18001FF80: "CertGetEnhancedKeyUsage" ??_C@_0BI@PFFJLCNF@CertGetEnhancedKeyUsage?$AA@
0x18001BBE0: "__cdecl _imp_memmove" __imp_memmove
0x18000C604: "long __cdecl GenAddImageSection(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_MODULE * __ptr64,unsigned long,struct _IMAGE_SECTION_HEADER * __ptr64)" ?GenAddImageSection@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_MODULE@@KPEAU_IMAGE_SECTION_HEADER@@@Z
0x18001DCA0: "GenAllocateModuleObject.GenImage" ??_C@_0EG@ENLELACC@GenAllocateModuleObject?4GenImage@
0x180007A40: "public: virtual long __cdecl Win32LiveSystemProvider::EnumUnloadedModules(unsigned short * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64) __ptr64" ?EnumUnloadedModules@Win32LiveSystemProvider@@UEAAJPEAGKPEA_KPEAK22@Z
0x180020200: "StartServiceW" ??_C@_0O@JGHHODOA@StartServiceW?$AA@
0x18001FEE8: "CertFindChainInStore" ??_C@_0BF@JOPNPAKK@CertFindChainInStore?$AA@
0x180014DC0: "public: __cdecl NtWin32LiveSystemProvider::NtWin32LiveSystemProvider(class MiniDumpAllocationProvider * __ptr64,class MiniDumpStatusProvider * __ptr64,unsigned long) __ptr64" ??0NtWin32LiveSystemProvider@@QEAA@PEAVMiniDumpAllocationProvider@@PEAVMiniDumpStatusProvider@@K@Z
0x18001F840: "api-ms-win-core-windowserrorrepo" ??_C@_0DB@OKLENCA@api?9ms?9win?9core?9windowserrorrepo@
0x18001D630: "VerQueryValueA" ??_C@_0P@EGBPEC@VerQueryValueA?$AA@
0x18001FB40: "CoReleaseMarshalData" ??_C@_0BF@MEKIJBIA@CoReleaseMarshalData?$AA@
0x18001BD28: "__cdecl _xt_z" __xt_z
0x18001C910: "WriteFullMemory virtual memory l" ??_C@_0HD@HEABGJOC@WriteFullMemory?5virtual?5memory?5l@
0x18001D2C8: "sychpe32" ??_C@_1BC@NBHLBKDF@?$AAs?$AAy?$AAc?$AAh?$AAp?$AAe?$AA3?$AA2?$AA?$AA@
0x180017270: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetCpuPowerInfo(unsigned long,struct _PROCESSOR_POWER_INFORMATION * __ptr64,unsigned long * __ptr64) __ptr64" ?GetCpuPowerInfo@NtWin32LiveSystemProvider@@UEAAJKPEAU_PROCESSOR_POWER_INFORMATION@@PEAK@Z
0x18001FBB8: "RoInitialize" ??_C@_0N@PPOMPGGK@RoInitialize?$AA@
0x18001E668: "RtlQueryProcessDebugInformation" ??_C@_0CA@CHDGPPCA@RtlQueryProcessDebugInformation?$AA@
0x18001E8E0: "RtlGetFunctionTableListHead" ??_C@_0BM@KFDLLAGC@RtlGetFunctionTableListHead?$AA@
0x18001B628: "const NtWin32LiveSystemProvider::`vftable'{for `MiniDumpSystemProvider'}" ??_7NtWin32LiveSystemProvider@@6BMiniDumpSystemProvider@@@
0x18001BC08: "__cdecl _imp_malloc" __imp_malloc
0x1800266B0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_DownlevelKernel32L1CallNames" ?g_DownlevelKernel32L1CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001BBD0: "__cdecl _imp__purecall" __imp__purecall
0x18000CA80: "long __cdecl GenAddThreadStack(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _INTERNAL_THREAD * __ptr64,unsigned __int64,unsigned long)" ?GenAddThreadStack@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_INTERNAL_THREAD@@_KK@Z
0x18001F578: "SetupComm" ??_C@_09CJIAILFL@SetupComm?$AA@
0x180012D40: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::ReadAllVirtual(void * __ptr64,unsigned __int64,void * __ptr64,unsigned long) __ptr64" ?ReadAllVirtual@PssNtWin32LiveSystemProvider@@UEAAJPEAX_K0K@Z
0x180004370: "long __cdecl WriteMemoryInfo(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?WriteMemoryInfo@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x18001B9B8: "__cdecl _imp_WriteFile" __imp_WriteFile
0x18000F320: "public: virtual long __cdecl GenClrDataTarget::GetMachineType(unsigned int * __ptr64) __ptr64" ?GetMachineType@GenClrDataTarget@@UEAAJPEAI@Z
0x1800157B0: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetThreadContext(void * __ptr64,void * __ptr64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64) __ptr64" ?GetThreadContext@NtWin32LiveSystemProvider@@UEAAJPEAX00KPEA_K11@Z
0x180019B90: "__cdecl _scrt_dllmain_after_initialize_c" __scrt_dllmain_after_initialize_c
0x18001BC10: "__cdecl _imp__o_towlower" __imp__o_towlower
0x18001E830: "Semaphore" ??_C@_1BE@NPGPGCB@?$AAS?$AAe?$AAm?$AAa?$AAp?$AAh?$AAo?$AAr?$AAe?$AA?$AA@
0x180018E90: "public: virtual long __cdecl StackProviderDataTarget::GetThreadContext(unsigned long,unsigned long,unsigned long,unsigned char * __ptr64) __ptr64" ?GetThreadContext@StackProviderDataTarget@@UEAAJKKKPEAE@Z
0x18001D4F8: "VerifierEnumerateResource" ??_C@_0BK@HKCFHGKD@VerifierEnumerateResource?$AA@
0x18001CDF0: "Module32Next" ??_C@_0N@KIGOLBLC@Module32Next?$AA@
0x180025318: "struct _SECURITY_BASE_CALLS volatile g_SecurityBaseCalls" ?g_SecurityBaseCalls@@3U_SECURITY_BASE_CALLS@@C
0x1800252F8: "struct _EVENTLOG_LEGACY_CALLS volatile g_EventlogLegacyCalls" ?g_EventlogLegacyCalls@@3U_EVENTLOG_LEGACY_CALLS@@C
0x180027850: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreToolHelpCallNames" ?g_CoreToolHelpCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001B340: "const StackProviderDataTarget::`vftable'" ??_7StackProviderDataTarget@@6B@
0x18001B9A0: "__cdecl _imp_GetFileSize" __imp_GetFileSize
0x180025238: "struct _CORE_CONSOLE_CALLS volatile g_CoreConsoleCalls" ?g_CoreConsoleCalls@@3U_CORE_CONSOLE_CALLS@@C
0x180020100: "GetEventLogInformation" ??_C@_0BH@OPDOCNNK@GetEventLogInformation?$AA@
0x180027070: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreProcessSecurityCallNames" ?g_CoreProcessSecurityCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x1800085C0: "public: virtual long __cdecl Win32LiveSystemProvider::GetImageVersionInfo(void * __ptr64,unsigned short const * __ptr64,unsigned __int64,struct tagVS_FIXEDFILEINFO * __ptr64) __ptr64" ?GetImageVersionInfo@Win32LiveSystemProvider@@UEAAJPEAXPEBG_KPEAUtagVS_FIXEDFILEINFO@@@Z
0x18001DDB0: "ProcessToken(%d,%I64x,%d,%d)" ??_C@_0BN@NHHODFON@ProcessToken?$CI?$CFd?0?$CFI64x?0?$CFd?0?$CFd?$CJ?$AA@
0x18001FD98: "PathIsRelativeW" ??_C@_0BA@LNFCGJPD@PathIsRelativeW?$AA@
0x18001F7E8: "api-ms-win-core-com-l1-1-1.dll" ??_C@_0BP@IJFPPCHL@api?9ms?9win?9core?9com?9l1?91?91?4dll?$AA@
0x180019C34: "__cdecl _scrt_dllmain_exception_filter" __scrt_dllmain_exception_filter
0x1800197A0: "__cdecl _report_gsfailure" __report_gsfailure
0x18000B3F0: "[thunk]:public: virtual void * __ptr64 __cdecl Win32LiveSystemProvider::`vector deleting destructor'`adjustor{8}' (unsigned int) __ptr64" ??_EWin32LiveSystemProvider@@W7EAAPEAXI@Z
0x180019314: "__cdecl _local_stdio_printf_options" __local_stdio_printf_options
0x18001EB18: "SymCleanup" ??_C@_0L@GDMHENGB@SymCleanup?$AA@
0x18001FA08: "api-ms-win-core-psapi-l1-1-0.dll" ??_C@_0CB@IFLMDHML@api?9ms?9win?9core?9psapi?9l1?91?90?4dll@
0x180007E70: "public: virtual long __cdecl Win32LiveSystemProvider::GetOsInfo(unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64,unsigned short * __ptr64) __ptr64" ?GetOsInfo@Win32LiveSystemProvider@@UEAAJPEAK000PEAG11@Z
0x18001FCA0: "VariantCopy" ??_C@_0M@EFCLFKLH@VariantCopy?$AA@
0x1800251E0: "struct _CORE_URL_CALLS volatile g_CoreUrlCalls" ?g_CoreUrlCalls@@3U_CORE_URL_CALLS@@C
0x18001C8A8: "WriteFullMemory.Memory.Write(0x%" ??_C@_0DC@FAIFLJFM@WriteFullMemory?4Memory?4Write?$CI0x?$CF@
0x180027480: "struct _DYNAMIC_CALLS_DESC volatile g_CoreJobL2CallsDesc" ?g_CoreJobL2CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001E918: "RtlGetUnloadEventTraceEx" ??_C@_0BJ@MPGODMAO@RtlGetUnloadEventTraceEx?$AA@
0x1800083E0: "public: virtual long __cdecl Win32LiveSystemProvider::GetImageHeaderInfo(void * __ptr64,unsigned short const * __ptr64,unsigned __int64,unsigned char * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64,unsigned long * __ptr64) __ptr64" ?GetImageHeaderInfo@Win32LiveSystemProvider@@UEAAJPEAXPEBG_KPEAEPEAK4444@Z
0x18000F590: "public: virtual long __cdecl GenClrDataTarget::Request(unsigned int,unsigned int,unsigned char * __ptr64,unsigned int,unsigned char * __ptr64) __ptr64" ?Request@GenClrDataTarget@@UEAAJIIPEAEI0@Z
0x1800261B0: "struct _DYNAMIC_CALLS_DESC volatile g_Ole32CallsDesc" ?g_Ole32CallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180012664: "public: virtual __cdecl PssNtWin32LiveSystemProvider::~PssNtWin32LiveSystemProvider(void) __ptr64" ??1PssNtWin32LiveSystemProvider@@UEAA@XZ
0x18001E810: "Event" ??_C@_1M@JJBFPLJB@?$AAE?$AAv?$AAe?$AAn?$AAt?$AA?$AA@
0x180007A40: "public: virtual unsigned long __cdecl GenClrDataTarget::AddRef(void) __ptr64" ?AddRef@GenClrDataTarget@@UEAAKXZ
0x1800235E0: "struct __type_info_node __type_info_root_node" ?__type_info_root_node@@3U__type_info_node@@A
0x18001CB80: "ARM" ??_C@_17FHNCMLPJ@?$AAA?$AAR?$AAM?$AA?$AA@
0x180026480: "struct _DYNAMIC_CALL_NAME volatile * volatile g_CoreTimeZoneCallNames" ?g_CoreTimeZoneCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001FA30: "GetUserNameExW" ??_C@_0P@NGNKGLOD@GetUserNameExW?$AA@
0x1800112B0: "public: virtual long __cdecl CallbackOutputProvider::Finish(void) __ptr64" ?Finish@CallbackOutputProvider@@UEAAJXZ
0x18001C568: "CalculateSizeForSystemInfo.GetOs" ??_C@_0DJ@HGGKIONM@CalculateSizeForSystemInfo?4GetOs@
0x18001E3D0: "GenWriteHandleData.Info.Write(0x" ??_C@_0DG@GAIJKPHA@GenWriteHandleData?4Info?4Write?$CI0x@
0x180006D9C: "public: virtual void * __ptr64 __cdecl Win32LiveSystemProvider::`vector deleting destructor'(unsigned int) __ptr64" ??_EWin32LiveSystemProvider@@UEAAPEAXI@Z
0x180027C60: "struct _DYNAMIC_CALL_NAME volatile * volatile g_VersionCallNames" ?g_VersionCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001EDE8: "RtlAnsiStringToUnicodeString" ??_C@_0BN@PPLEAEDO@RtlAnsiStringToUnicodeString?$AA@
0x180020188: "ReportEventA" ??_C@_0N@PKNECLKP@ReportEventA?$AA@
0x180010A5C: "long __cdecl GenWriteHandleData(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64)" ?GenWriteHandleData@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@PEAU_MINIDUMP_STREAM_INFO@@@Z
0x180009FF0: "public: virtual long __cdecl Win32LiveSystemProvider::CheckForAuxProvider(unsigned short * __ptr64,unsigned short * __ptr64,unsigned long) __ptr64" ?CheckForAuxProvider@Win32LiveSystemProvider@@UEAAJPEAG0K@Z
0x18001BA28: "__cdecl _imp_LoadResource" __imp_LoadResource
0x18001EEF8: "RtlUnicodeStringToAnsiString" ??_C@_0BN@IINAALHC@RtlUnicodeStringToAnsiString?$AA@
0x180007E20: "public: virtual void __cdecl Win32LiveSystemProvider::GetPointerSize(unsigned long * __ptr64) __ptr64" ?GetPointerSize@Win32LiveSystemProvider@@UEAAXPEAK@Z
0x180026130: "struct _DYNAMIC_CALL_NAME volatile * volatile g_UserEnvCallNames" ?g_UserEnvCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x1800183E4: "struct _IMAGE_NT_HEADERS64 * __ptr64 __cdecl GenImageNtHeader(void * __ptr64,struct _IMAGE_NT_HEADERS64 * __ptr64)" ?GenImageNtHeader@@YAPEAU_IMAGE_NT_HEADERS64@@PEAXPEAU1@@Z
0x18001FA78: "GetThreadDesktop" ??_C@_0BB@KHBHHLKH@GetThreadDesktop?$AA@
0x18001ED60: "NtOpenProcess" ??_C@_0O@JGCNKEPA@NtOpenProcess?$AA@
0x180013BB0: "private: static long __cdecl PssNtWin32LiveSystemProvider::s_RtlQpdiReadMemory(void * __ptr64,void * __ptr64,void * __ptr64,unsigned __int64,unsigned __int64 * __ptr64)" ?s_RtlQpdiReadMemory@PssNtWin32LiveSystemProvider@@CAJPEAX00_KPEA_K@Z
0x18001D4C0: "powrprof.dll" ??_C@_0N@MKKJEGPI@powrprof?4dll?$AA@
0x180021AA4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0
0x180021A68: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-localregistry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-localregistry-l1-1-0
0x180009820: "public: virtual void __cdecl Win32LiveSystemProvider::FreeProcessIptTrace(void * __ptr64) __ptr64" ?FreeProcessIptTrace@Win32LiveSystemProvider@@UEAAXPEAX@Z
0x180025098: "struct _COREWINRT_CALLS volatile g_CoreWinRTCalls" ?g_CoreWinRTCalls@@3U_COREWINRT_CALLS@@C
0x180017950: "public: virtual long __cdecl NtWin32LiveSystemProvider::OpenToken(unsigned long,unsigned long,void * __ptr64,void * __ptr64 * __ptr64) __ptr64" ?OpenToken@NtWin32LiveSystemProvider@@UEAAJKKPEAXPEAPEAX@Z
0x18001EDD0: "NtWaitForDebugEvent" ??_C@_0BE@FJNCDLOK@NtWaitForDebugEvent?$AA@
0x18001ED98: "NtSetInformationDebugObject" ??_C@_0BM@JOMKIEBB@NtSetInformationDebugObject?$AA@
0x1800096A0: "public: virtual void __cdecl PssNtWin32LiveSystemProvider::CloseThread(void * __ptr64) __ptr64" ?CloseThread@PssNtWin32LiveSystemProvider@@UEAAXPEAX@Z
0x18001E440: "GenWriteHandleData.Desc.Write(0x" ??_C@_0DD@IPCLEKD@GenWriteHandleData?4Desc?4Write?$CI0x@
0x18001F328: "DosDateTimeToFileTime" ??_C@_0BG@OEMDOHFG@DosDateTimeToFileTime?$AA@
0x1800259E0: "struct _NTDLL_CALLS volatile g_NtDllCalls" ?g_NtDllCalls@@3U_NTDLL_CALLS@@C
0x18001BBF8: "__cdecl _imp__wsplitpath_s" __imp__wsplitpath_s
0x18001BAC0: "__cdecl _imp_MapViewOfFile" __imp_MapViewOfFile
0x18001E728: "PssWalkMarkerGetPosition" ??_C@_0BJ@PHBJCJEJ@PssWalkMarkerGetPosition?$AA@
0x180013460: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::GetThreadTebInfo(void * __ptr64,void * __ptr64,unsigned __int64 * __ptr64,unsigned long * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,bool) __ptr64" ?GetThreadTebInfo@PssNtWin32LiveSystemProvider@@UEAAJPEAX0PEA_KPEAK11111_N@Z
0x180026960: "struct _DYNAMIC_CALLS_DESC volatile g_CorePsapiCallsDesc" ?g_CorePsapiCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x180026A60: "struct _DYNAMIC_CALL_NAME volatile * volatile g_Kernel32CallNames" ?g_Kernel32CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x180026830: "struct _DYNAMIC_CALL_NAME volatile * volatile g_ExtKernel32PackageL1CallNames" ?g_ExtKernel32PackageL1CallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001BBB0: "__cdecl _imp__configure_narrow_argv" __imp__configure_narrow_argv
0x180002E7C: "long __cdecl FilterOrScanMemory(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?FilterOrScanMemory@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@@Z
0x180001CB8: "long __cdecl WriteThreadList(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64)" ?WriteThreadList@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@@Z
0x180021B08: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0
0x1800260F0: "struct _DYNAMIC_CALLS_DESC volatile g_ServiceManagementCallsDesc" ?g_ServiceManagementCallsDesc@@3U_DYNAMIC_CALLS_DESC@@C
0x18001E578: "__cdecl GUID_6d05fae3_189c_4630_a6dc_1c251e1c01ab" _GUID_6d05fae3_189c_4630_a6dc_1c251e1c01ab
0x180015800: "public: virtual long __cdecl NtWin32LiveSystemProvider::GetThreadContextEx(void * __ptr64,void * __ptr64,void * __ptr64,unsigned long,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned __int64 * __ptr64,unsigned long,bool) __ptr64" ?GetThreadContextEx@NtWin32LiveSystemProvider@@UEAAJPEAX00KPEA_K11K_N@Z
0x18001BC40: "__cdecl _imp___std_type_info_destroy_list" __imp___std_type_info_destroy_list
0x180014F2C: "public: virtual __cdecl NtWin32LiveSystemProvider::~NtWin32LiveSystemProvider(void) __ptr64" ??1NtWin32LiveSystemProvider@@UEAA@XZ
0x180007E30: "public: virtual void __cdecl Win32LiveSystemProvider::GetPageSize(unsigned long * __ptr64) __ptr64" ?GetPageSize@Win32LiveSystemProvider@@UEAAXPEAK@Z
0x18001F8F0: "api-ms-win-core-file-l2-1-1.dll" ??_C@_0CA@GJEHDJC@api?9ms?9win?9core?9file?9l2?91?91?4dll?$AA@
0x18001F138: "SetThreadContext" ??_C@_0BB@KFKDMCFP@SetThreadContext?$AA@
0x18001BBA8: "__cdecl _imp__o__cexit" __imp__o__cexit
0x180008C20: "public: virtual long __cdecl Win32LiveSystemProvider::GetThreadOsInfo(void * __ptr64,void * __ptr64,struct _UMINIPROV_THREAD_INFO * __ptr64) __ptr64" ?GetThreadOsInfo@Win32LiveSystemProvider@@UEAAJPEAX0PEAU_UMINIPROV_THREAD_INFO@@@Z
0x18001D958: "ThreadToken_User(0x%08X,%d,%d,%d" ??_C@_0CC@OHPHLKKB@ThreadToken_User?$CI0x?$CF08X?0?$CFd?0?$CFd?0?$CFd@
0x18001BC00: "__cdecl _imp_free" __imp_free
0x180025000: "struct _CORE_VERSION_CALLS volatile g_CoreVersionCalls" ?g_CoreVersionCalls@@3U_CORE_VERSION_CALLS@@C
0x18001C990: "Could not update MINIDUMP_MEMORY" ??_C@_0GB@EJCNGMD@Could?5not?5update?5MINIDUMP_MEMORY@
0x180014550: "public: virtual long __cdecl PssNtWin32LiveSystemProvider::QueryMiscInformation(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?QueryMiscInformation@PssNtWin32LiveSystemProvider@@UEAAJPEAXKPEAK0K1@Z
0x18000B2C0: "public: virtual long __cdecl Win32FileOutputProvider::WriteAll(void * __ptr64,unsigned long) __ptr64" ?WriteAll@Win32FileOutputProvider@@UEAAJPEAXK@Z
0x180006644: "long __cdecl DetermineOutputProvider(class MiniDumpAllocationProvider * __ptr64,void * __ptr64,struct _MINIDUMP_CALLBACK_INFORMATION * __ptr64 const,class MiniDumpOutputProvider * __ptr64 * __ptr64)" ?DetermineOutputProvider@@YAJPEAVMiniDumpAllocationProvider@@PEAXQEAU_MINIDUMP_CALLBACK_INFORMATION@@PEAPEAVMiniDumpOutputProvider@@@Z
0x18001F568: "SetCommTimeouts" ??_C@_0BA@NHFMBHEE@SetCommTimeouts?$AA@
0x18001C4B0: "Module(0x%I64x, %ws) callback re" ??_C@_0CN@MADGAECI@Module?$CI0x?$CFI64x?0?5?$CFws?$CJ?5callback?5re@
0x180020088: "EnumServicesStatusExA" ??_C@_0BG@BMMFFGEL@EnumServicesStatusExA?$AA@
0x1800250E0: "struct _SERVICE_MANAGEMENT_CALLS volatile g_ServiceManagementCalls" ?g_ServiceManagementCalls@@3U_SERVICE_MANAGEMENT_CALLS@@C
0x18001F358: "FindResourceW" ??_C@_0O@IBILDNOM@FindResourceW?$AA@
0x18001BB78: api-ms-win-core-synch-l1-1-0_NULL_THUNK_DATA
0x1800268A0: "struct _DYNAMIC_CALL_NAME volatile * volatile g_VerifierCallNames" ?g_VerifierCallNames@@3RCU_DYNAMIC_CALL_NAME@@C
0x18001A34A: "__cdecl execute_onexit_table" _execute_onexit_table
0x18001F708: "api-ms-win-downlevel-kernel32-l1" ??_C@_0CJ@MFOGIEMH@api?9ms?9win?9downlevel?9kernel32?9l1@
0x18001DED8: "ProcessToken_RestrictedSids(0x%0" ??_C@_0CN@HFAJLDKA@ProcessToken_RestrictedSids?$CI0x?$CF0@
0x180001904: "long __cdecl WriteMemoryFromProcess(struct _MINIDUMP_STATE * __ptr64,struct _MINIDUMP_STREAM_INFO * __ptr64,struct _INTERNAL_PROCESS * __ptr64,unsigned __int64,unsigned long,enum MEMBLOCK_FILTER_TYPE,unsigned long,struct _VA_RANGE_REF * __ptr64,enum MEMBLOCK_TYPE,unsigned char,unsigned long * __ptr64)" ?WriteMemoryFromProcess@@YAJPEAU_MINIDUMP_STATE@@PEAU_MINIDUMP_STREAM_INFO@@PEAU_INTERNAL_PROCESS@@_KKW4MEMBLOCK_FILTER_TYPE@@KPEAU_VA_RANGE_REF@@W4MEMBLOCK_TYPE@@EPEAK@Z
0x18001A30E: memset
0x180021B30: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x180019894: "__cdecl _report_securityfailure" __report_securityfailure
0x180019290: "unsigned long __cdecl RunOnceObtainMrdataCommit(union _RTL_RUN_ONCE * __ptr64,void * __ptr64,void * __ptr64 * __ptr64)" ?RunOnceObtainMrdataCommit@@YAKPEAT_RTL_RUN_ONCE@@PEAXPEAPEAX@Z
0x1800253D0: "struct _CORE_MISC_CALLS volatile g_CoreMiscCalls" ?g_CoreMiscCalls@@3U_CORE_MISC_CALLS@@C
0x18001E988: "NtPowerInformation" ??_C@_0BD@EJALDNPB@NtPowerInformation?$AA@
0x180006B20: "public: virtual void * __ptr64 __cdecl MiniDumpVmHookedProvider::`vector deleting destructor'(unsigned int) __ptr64" ??_EMiniDumpVmHookedProvider@@UEAAPEAXI@Z
0x180025280: "struct _CRYPT32_CALLS volatile g_Crypt32Calls" ?g_Crypt32Calls@@3U_CRYPT32_CALLS@@C
0x180012320: "long __cdecl GenAddMemoryRange(struct _MINIDUMP_STATE * __ptr64,struct _INTERNAL_PROCESS * __ptr64,enum MEMBLOCK_TYPE,enum MEMBLOCK_FILTER_TYPE,unsigned __int64,unsigned __int64)" ?GenAddMemoryRange@@YAJPEAU_MINIDUMP_STATE@@PEAU_INTERNAL_PROCESS@@W4MEMBLOCK_TYPE@@W4MEMBLOCK_FILTER_TYPE@@_K4@Z
0x180023048: "unsigned __int64 `__local_stdio_scanf_options'::`2'::_OptionsStorage" ?_OptionsStorage@?1??__local_stdio_scanf_options@@9@4_KA

[JEB Decompiler by PNF Software]